VYPR
Unrated severityNVD Advisory· Published Jun 12, 2026· Updated Jun 12, 2026

CVE-2026-50629

CVE-2026-50629

Description

Apache CXF OAuth2 logs unsanitized clientId, enabling log injection that can forge entries or poison log analysis tools.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Apache CXF OAuth2 logs unsanitized clientId, enabling log injection that can forge entries or poison log analysis tools.

Vulnerability

Apache CXF versions for the cxf-rt-rs-security-oauth2 module before 4.1.7, and from 4.2.0 before 4.2.2, directly concatenate the clientId parameter from incoming HTTP requests into OAuth2 server log warning messages without sanitizing control characters [1]. This allows an attacker to inject arbitrary content, including fake log entries, into the server's log files [1].

Exploitation

An attacker must be able to send an HTTP request to an affected Apache CXF OAuth2 endpoint. The attacker includes malicious control characters (e.g., newline characters) within the clientId parameter value. The server logs a warning message that contains the unsanitized clientId, thereby injecting attacker-controlled content into the log output [1]. No authentication or special privileges are required beyond network access to the OAuth2 endpoint.

Impact

Successful exploitation allows an attacker to inject arbitrary log entries into the server's log files. This can be used to mislead security monitoring tools, conceal malicious activity, or cause log analysis systems to misinterpret events. The impact is limited to log injection; no data confidentiality or integrity beyond log file manipulation is directly compromised.

Mitigation

Users should upgrade to Apache CXF version 4.1.7 or 4.2.2, released on June 11, 2026, which fixes the issue [1]. No workarounds are described in the reference. The CVE severity is rated low [1].

AI Insight generated on Jun 12, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

2

News mentions

0

No linked articles in our index yet.