Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-50632

Опубликовано: 12 июн. 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.

A flaw was found in Apache CXF. This vulnerability, stemming from an incomplete fix for a previous issue, allows untrusted users who can configure Java Message Service (JMS) for Apache CXF to achieve arbitrary code execution. This could lead to a complete compromise of the affected system.

Отчет

This Important flaw in Apache CXF's JMS transport allows arbitrary code execution. The vulnerability occurs when untrusted users can configure Java Message Service (JMS) for Apache CXF, potentially leading to a complete system compromise. This risk is present in environments where JMS configuration is accessible to or managed by untrusted entities.

Меры по смягчению последствий

To mitigate this issue, ensure that only trusted administrators have the necessary permissions to configure Java Message Service (JMS) for Apache CXF. Restricting access to JMS configuration prevents untrusted users from exploiting this vulnerability. Review and enforce strict access controls on systems where Apache CXF is deployed with JMS transport.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7cxf-rt-transports-jmsFix deferred
Red Hat JBoss Enterprise Application Platform 7cxf-rt-transports-jmsFix deferred
Red Hat JBoss Enterprise Application Platform 8cxf-rt-transports-jmsAffected
Red Hat JBoss Enterprise Application Platform Expansion Packcxf-rt-transports-jmsNot affected
Red Hat Single Sign-On 7cxf-rt-transports-jmsFix deferred
Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16cxf-rt-transports-jmsFixedRHSA-2026:3739009.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-502
https://bugzilla.redhat.com/show_bug.cgi?id=2488304cxf: org.apache.cxf/cxf-rt-transports-jms: Apache CXF: Arbitrary code execution via untrusted JMS configuration

EPSS

Процентиль: 46%
0.00646
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
nvd
около 2 месяцев назад

A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.

CVSS3: 9.8
github
около 2 месяцев назад

A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.

EPSS

Процентиль: 46%
0.00646
Низкий

8.8 High

CVSS3