Description
In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client registration request verbatim, without validating it against an AS-defined allowlist. This could lead to a client self-assigning privileged scopes at registration time. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
Severity (CVSS)
| Base score | 9.1 |
|---|---|
| Severity | Critical |
| Version | CVSS 3.1 |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H |
| Provided by | CISA-ADP |
Weaknesses
- CWE-304 — CWE-304 Missing Critical Step in Authentication
Affected products
| Vendor | Product | Versions |
|---|---|---|
| Apache Software Foundation | Apache CXF | 0 to <3.6.12; 4.0.0 to <4.1.8; 4.2.0 to <4.2.3 |
References
Generated from the official CVE List on 07 Aug 2026 07:02 UTC.