CVE-2026-57818

Updated on 06 Aug 2026

Severity

8.1 High severity

Details

CVSS score
8.1
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Overview

About vulnerability

A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization code multiple times via concurrent requests, resulting in the issuance of multiple distinct, valid access tokens. Users are recommended to upgrade to versions 4.2.3, 4.1.8 or 3.6.12, which fix this issue.

Details

Affected product:
Apache CXF , Wildfly , camel , tika , wildfly
Affected packages:
cxf-services-sts @ 3.5.11 (+1940 more)

Fixes