CVE-2026-97468
Received Received - Intake

Apache CXF Security Token Validation Bypass via Hash Collision

Vulnerability report for CVE-2026-97468, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: Apache Software Foundation

Description

Apache CXF's STSTokenValidator and Security Token Service (STS) cached validated security tokens under a non-cryptographic 32-bit hash of the token (Java Arrays.hashCode/hashCode()), and treated a cache hit as proof that the presented token had already been validated. An attacker could craft a token (for example a UsernameToken or a self-signed SAML Assertion) whose hash collides with a cached entry. The token would then be accepted without password validation, signature trust verification or a call to the STS. This could let the attacker authenticate as another user and, through STS token validation or renewal, obtain STS-signed tokens for that identity. Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
Apache Software Foundation Apache CXF 4.2.0
Apache Software Foundation Apache CXF 4.0.0
Apache Software Foundation Apache CXF 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Apache CXF's STSTokenValidator and Security Token Service (STS) cached validated security tokens using a non-cryptographic 32-bit hash. An attacker could craft a token with a hash collision to bypass validation, allowing authentication as another user without proper checks.

Detection Guidance

Detecting this vulnerability requires checking Apache CXF versions and analyzing token validation logs. Verify installed versions with commands like 'cxf-rt-ws-security --version' or checking Maven/Gradle dependencies. Monitor STS logs for unexpected token validations or authentication bypass attempts.

Impact Analysis

An attacker could impersonate another user, gain unauthorized access to systems, and obtain STS-signed tokens for that identity, potentially leading to data breaches or privilege escalation.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating compliance requirements for data protection and access control in standards like GDPR and HIPAA.

Mitigation Strategies

Upgrade Apache CXF to versions 4.2.4, 4.1.9, or 3.6.13 immediately. Disable caching of validated tokens if possible. Review STS configurations to ensure strict token validation. Monitor for unauthorized access attempts or unusual authentication patterns.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-97468. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart