High severity7.4NVD Advisory· Published Jun 12, 2026· Updated Aug 7, 2026
CVE-2026-50631
CVE-2026-50631
Description
A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-use semantics and generate multiple valid Access Tokens, when 'recycleRefreshTokens' is set to false. A leaked refresh token can be replayed concurrently by multiple attackers or threads. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fixes this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.cxf:cxf-rt-rs-security-oauth2Maven | >= 4.2.0, < 4.2.2 | 4.2.2 |
org.apache.cxf:cxf-rt-rs-security-oauth2Maven | < 4.1.7 | 4.1.7 |
Affected products
3- Range: versions prior to 4.2.2, 4.1.7, or 3.6.12
Patches
Vulnerability mechanics
References
4- www.openwall.com/lists/oss-security/2026/06/11/8nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-83r6-96m8-r52pghsaADVISORY
- lists.apache.org/thread/s83t3x4r626o9h8rt0ryr1w7w53l1vv8nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-50631ghsaADVISORY
News mentions
0No linked articles in our index yet.