CVE-2026-50633

Updated on 12 Jun 2026

Severity

Awaiting Analysis

Details

CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Overview

About vulnerability

A JNDI Injection vulnerability has been discovered in Apache CXF’s JCA integration module, which can allow for code execution, if an attacker is able to manipulate the JCA deployment descriptor (ra.xml) or runtime activation parameters. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.

Details

Affected product:
Apache CXF , Wildfly , tika , wildfly
Affected packages:
wildfly-transactions @ 27.0.1.Final (+1248 more)