← Vulnerability feed

Vulnerability record · CVE-2026-44417 · published 22 May 2026

CVE-2026-44417: Apache cxf improper input validation vulnerability

Apache · Cxf

The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.

7.5 CVSS 3.1 High EPSS 0.90% · top 41.8% CWE-20 · Improper input validationCWE-15 · CWE-15
7.5CVSS 3.1 base score
0.90%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
5References
23 Jul 2026Last modified by NVD

Description

The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-44417 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2012-2379Apache cxf vulnerabilityApache CXF 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1, when a Supporting Token specifies a child WS-SecurityPolicy 1.1 or 1.2 pol…EPSS 4.1%9.8CVE-2026-68079Apache cxf authentication bypass by capture-replay vulnerabilityIn Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the im…EPSS 0.68%9.8CVE-2026-66909Apache cxf deserialization of untrusted data vulnerabilityApache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in pla…EPSS 1.1%9.8CVE-2026-49875Apache cxf xml external entity (xxe) vulnerabilityApache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configuration…EPSS 0.81%9.8CVE-2026-50628Apache cxf improper input validation vulnerabilityA logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other…EPSS 1.0%9.8CVE-2026-44930Apache cxf ldap injection vulnerabilityAn LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certi…EPSS 0.51%9.8CVE-2025-48913Apache cxf improper input validation vulnerabilityIf untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution cap…EPSS 0.82%9.8CVE-2022-46364Apache cxf server-side request forgery (ssrf) vulnerabilityA SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attack…EPSS 2.2%

Source: NIST National Vulnerability Database (record CVE-2026-44417), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.