Critical severity9.1NVD Advisory· Published Aug 6, 2026· Updated Aug 7, 2026
CVE-2026-61466
CVE-2026-61466
Description
In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the scope value supplied in the client registration request verbatim, without validating it against an AS-defined allowlist. This could lead to a client self-assigning privileged scopes at registration time. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
2- lists.apache.org/thread/2l1r16g79tpxd7fzrzr2q9oscwrjgljsnvdMailing ListVendor Advisory
- www.openwall.com/lists/oss-security/2026/08/06/21nvd
News mentions
1- Apache Projects Hit by 25 Vulnerabilities: Fory, CXF, APR-util, Answer, Polaris AffectedVypr Intelligence · Aug 7, 2026