# CVE-2026-50627

## Summary

- **CVE ID:** CVE-2026-50627
- **Severity:** UNKNOWN
- **CVSS Score:** 0.02 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H)
- **CWE:** CWE-289
- **Published:** Jun 12, 2026
- **Last Modified:** Aug 10, 2026

## Description

The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one Resource Server to be successfully replayed against a completely different Resource Server, leading to Token Confusion/Routing attacks. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.

## Affected Products

- Apache Software Foundation — Apache CXF (4.2.0)
- Apache Software Foundation — Apache CXF (0)
- Apache Software Foundation — Apache CXF (4.0.0)

## References

- [CNA](https://lists.apache.org/thread/0jfzz9q992957b99tw7hodcqjfyxwb1m)
- [CVE](http://www.openwall.com/lists/oss-security/2026/06/11/4)
- [redhat-SADP](https://access.redhat.com/security/cve/CVE-2026-50627)
- [redhat-SADP](https://bugzilla.redhat.com/show_bug.cgi?id=2488298)
- [redhat-SADP](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50627.json)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:37390)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.45%
- **EPSS Percentile:** 37.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._