LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-57818

apache · cxf

Published
CVSS8.1
Severityhigh
WeaknessCWE-367
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization code multiple times via concurrent requests, resulting in the issuance of multiple distinct, valid access tokens. Users are recommended to upgrade to versions 4.2.3, 4.1.8 or 3.6.12, which fix this issue.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-57818

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-57818.