<Vulnerability name="CVE-2026-68481">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Moderate</ThreatSeverity>
    <PublicDate>2026-08-06T11:22:37</PublicDate>
    <Bugzilla id="2511994" url="https://bugzilla.redhat.com/show_bug.cgi?id=2511994" xml:lang="en:us">
org.apache.cxf/cxf-rt-rs-security-oauth2: Apache CXF: Revocation bypass allows unauthorized access
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>5.4</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-303</CWE>
    <Details xml:lang="en:us" source="Mitre">
In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully, and TokenIntrospectionService reports active:true. The same applies to refresh tokens. This violates the RFC stipulations that 'The authorization server MUST invalidate the token.' and 'introspection of a revoked token MUST return {"active":false}'. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in Apache CXF. This vulnerability affects the DefaultEncryptingOAuthDataProvider, where revoked access and refresh tokens can still be successfully decrypted and reported as active. This bypasses the intended token revocation process, potentially allowing unauthorized access to systems or data even after a user's permissions have been withdrawn.
    </Details>
    <Statement xml:lang="en:us">
Moderate: This flaw in Apache CXF's OAuth2 token handling allows previously revoked access and refresh tokens to remain valid. This bypasses intended revocation mechanisms, potentially enabling unauthorized access to resources in applications deployed on affected Red Hat platforms that utilize the DefaultEncryptingOAuthDataProvider.
    </Statement>
    <Mitigation xml:lang="en:us">
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
    </Mitigation>
    <PackageState cpe="cpe:/a:redhat:camel_spring_boot:4">
        <ProductName>Red Hat build of Apache Camel for Spring Boot 4</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>cxf-rt-rs-security-oauth2</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jbosseapxp">
        <ProductName>Red Hat JBoss Enterprise Application Platform Expansion Pack</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>cxf-rt-rs-security-oauth2</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jboss_enterprise_web_server:5">
        <ProductName>Red Hat JBoss Web Server 5</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>cxf-rt-rs-security-oauth2</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-68481
https://nvd.nist.gov/vuln/detail/CVE-2026-68481
https://lists.apache.org/thread/88c0h10yjb2b8201o1km3st71fs2zw2b
    </References>
</Vulnerability>