← Back to CVE search

CVE-2026-50633

Apache CXF

Description

A JNDI Injection vulnerability has been discovered in Apache CXF-s JCA integration module, which can allow for code execution, if an attacker is able to manipulate the JCA deployment descriptor (ra.xml) or runtime activation parameters. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fixes this issue.

CVSS 8.1EPSS 0.861%Risk 0.87
View source
Published
2026-06-12 10:16:23
Affected versions
<4.2.2, <4.1.7
Type
Library
Last modified
2026-08-07 13:16:51
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H