High severity8.1NVD Advisory· Published Aug 6, 2026· Updated Aug 7, 2026
CVE-2026-57818
CVE-2026-57818
Description
A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization code multiple times via concurrent requests, resulting in the issuance of multiple distinct, valid access tokens. Users are recommended to upgrade to versions 4.2.3, 4.1.8 or 3.6.12, which fix this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: before 4.2.3, 4.1.8, 3.6.12
Patches
Vulnerability mechanics
References
2- lists.apache.org/thread/7q08mz8bcbosp25wok7gr537zlp15mfznvdMailing ListVendor Advisory
- www.openwall.com/lists/oss-security/2026/08/06/20nvd
News mentions
1- Apache Projects Hit by 25 Vulnerabilities: Fory, CXF, APR-util, Answer, Polaris AffectedVypr Intelligence · Aug 7, 2026