Description
Improper enforcement of single-use authorization code semantics in the JPA OAuth2 authorization code grant provider in Apache CXFallows a remote attacker to obtain multiple valid access tokens from a single authorization code via concurrent token exchange requests that race the non-atomic find-then-delete operation against a shared relational database under READ_COMMITTED isolation. Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fixes this issue.
Published: 2026-10-09
Score: n/a
EPSS: n/a
KEV: No
Impact: Unauthorized Replay of Authorization Code
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in Apache CXF’s JPA OAuth2 authorization code grant provider permits a remote attacker to obtain multiple distinct access tokens from a single authorization code. The flaw arises from a race condition between a non‑atomic find and delete operation that targets a shared relational database operating under READ_COMMITTED isolation. Because the provider incorrectly permits concurrent token exchanges, the single‑use constraint is violated, allowing the attacker to replay the code and gain unauthorized access to protected resources. The issue is a classic example of flawed atomicity and concurrency control (CWE‑367).

Affected Systems

Apache Software Foundation’s Apache CXF is impacted. Versions older than 4.2.4, 4.1.9, or 3.6.13 lack the fix and therefore are vulnerable. No other vendors or products are listed as affected in this advisory.

Risk and Exploitability

The CVSS score and EPSS are not provided, and the vulnerability is not listed in the CISA KEV catalog, so an official severity assessment is unavailable. Nevertheless, the exploit requires only concurrent HTTP requests to the token exchange endpoint and no special privileges beyond those needed to initiate a token request. Any client capable of sending such requests can generate an unlimited number of tokens until administrative limits or logs trigger suspicion. The absence of an EPSS rating suggests that exploitation may not yet have been observed in the wild, but the design flaw presents a high risk for credential misuse and should be treated as significant.

Generated by OpenCVE AI on October 9, 2026 at 11:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache CXF to version 4.2.4, 4.1.9, or 3.6.13 to apply the atomic operation fix.
  • Review your OAuth2 configuration to enforce single‑use authorization codes and periodically audit token issuance logs.
  • If upgrading is delayed, increase the database transaction isolation level to SERIALIZABLE to reduce race conditions as a temporary mitigation.
  • Monitor authentication activity for abnormal token issuance patterns that may indicate concurrent exploitation attempts.

Generated by OpenCVE AI on October 9, 2026 at 11:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 10:30:00 +0000

Type Values Removed Values Added
Description Improper enforcement of single-use authorization code semantics in the JPA OAuth2 authorization code grant provider in Apache CXFallows a remote attacker to obtain multiple valid access tokens from a single authorization code via concurrent token exchange requests that race the non-atomic find-then-delete operation against a shared relational database under READ_COMMITTED isolation. Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fixes this issue.
Title Apache CXF: JPA authorization-code consume is non-atomic
Weaknesses CWE-367
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-09T11:07:57.643Z

Reserved: 2026-08-11T10:44:12.783Z

Link: CVE-2026-73179

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T11:17:02.817

Modified: 2026-10-09T11:17:02.817

Link: CVE-2026-73179

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T11:30:06Z

Weaknesses
  • CWE-367

    Time-of-check Time-of-use (TOCTOU) Race Condition