CVE-2026-68079
In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the implementation of the removeCodeGrant functionality. This violates the RFC requirement that "The authorization code MUST NOT be used more than once." Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.40%
- CWE
- CWE-294
- Published
- 2026-08-06
- Last modified
- 2026-08-07
Affected products
- Apache Software Foundation Apache CXF
- Apache Software Foundation Apache CXF
- Apache Software Foundation Apache CXF
Weakness type
Related vulnerabilities
- CVE-2026-55250 — Maravel-Framework Token Replay Vulnerability via Premature JWT Blacklist Eviction in Tagged Caches
- CVE-2026-84003 — Microsoft Authentication Library (MSAL) for Node.js Spoofing Vulnerability
- CVE-2026-69676 — Windows Kerberos Remote Code Execution Vulnerability
- CVE-2026-73312 — XenForo < 2.3.13 Refresh Token Replay via Expired Access Token
- CVE-2026-73311 — XenForo < 2.3.13 OAuth2 Authorization Code Reuse
- CVE-2022-51016 — PocketMine-MP 3.x before 3.27.0 Authentication Bypass via Login Replay
- CVE-2026-86219 — Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step
- CVE-2026-75034 — Rancher: SAML Assertion Replay