CYBER CODE RED

Get real-time updates on Telegram

Verified

CVE-2026-97791: Apache CXF 4.2.0 to before 4.2.4, 4.0.0 to before 4.1.9, 0 to before 3.6.13

Affected technology

Apache CXF · 4.2.0 to before 4.2.4, 4.0.0 to before 4.1.9, 0 to before 3.6.13
Apache Software Foundation

Component: Not specified by the source

What an attacker can do

Unauthenticated attacker could send a forged assertion signed with an untrusted certificate while legitimate requests were being processed, and it could be accepted as trusted without ever reaching the STS.

Published

KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-97791.html