VYPR
High severity8.1NVD Advisory· Published Jun 12, 2026· Updated Aug 7, 2026

CVE-2026-50633

CVE-2026-50633

Description

A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to manipulate the JCA deployment descriptor (ra.xml) or runtime activation parameters. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fixes this issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.cxf:cxf-integration-jcaMaven
>= 4.2.0, < 4.2.24.2.2
org.apache.cxf:cxf-integration-jcaMaven
< 4.1.74.1.7

Affected products

2
  • Apache/Cxf2 versions
    cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:*range: <4.1.7
    • (no CPE)range: before 4.2.2, 4.1.7, or 3.6.12

Patches

Vulnerability mechanics

References

8

News mentions

1