# CVE-2026-68481

## Summary

- **CVE ID:** CVE-2026-68481
- **Severity:** HIGH
- **CVSS Score:** 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
- **CWE:** CWE-672
- **Published:** Aug 6, 2026
- **Last Modified:** Aug 7, 2026

## Description

In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully, and TokenIntrospectionService reports active:true. The same applies to refresh tokens. This violates the RFC stipulations that 'The authorization server MUST invalidate the token.' and 'introspection of a revoked token MUST return {"active":false}'. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.

## Affected Products

- Apache Software Foundation — Apache CXF (4.2.0)
- Apache Software Foundation — Apache CXF (4.0.0)
- Apache Software Foundation — Apache CXF (0)

## References

- [CNA](https://lists.apache.org/thread/88c0h10yjb2b8201o1km3st71fs2zw2b)
- [CVE](http://www.openwall.com/lists/oss-security/2026/08/06/25)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.43%
- **EPSS Percentile:** 35.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._