Home

Description

A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to manipulate the JCA deployment descriptor (ra.xml) or runtime activation parameters. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.

PUBLISHED Reserved 2026-06-05 | Published 2026-06-12 | Updated 2026-06-12 | Assigner apache

Problem types

CWE-20 Improper Input Validation

Product status

Default status
unaffected

4.2.0 (semver) before 4.2.2
affected

Any version before 4.1.7
affected

Credits

Venkatraman Kumar (r3dw0lfsec), Securin finder

References

www.openwall.com/lists/oss-security/2026/06/11/10

lists.apache.org/thread/1czhgovkgzdkyp3t61wthn0foogh2grf vendor-advisory

cve.org (CVE-2026-50633)

nvd.nist.gov (CVE-2026-50633)

Download JSON