CVE-2026-49875
Apache CXF is vulnerable to a critical flaw that lets attackers use external entities to read files or execute code on the server. The issue arises because the library builds a SAX parser without proper security settings.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Apache CXF users, especially those running versions older than 4.2.2 or 4.1.7.
Real-world impact
An attacker could read sensitive files, access internal network resources, or run arbitrary code on the affected server, potentially compromising the entire application.
Why this severity
The CVSS score of 9.8 reflects that the vulnerability is exploitable over the network, requires no user interaction, and can lead to full compromise of confidentiality, integrity, and availability.
What to do about it
- 01Upgrade Apache CXF to version 4.2.2 or later, or to version 4.1.7 or later.
- 02Restart the application or service to ensure the new version is in use.
NVD-referenced vendor advisory
Timeline
- Jun 12, 2026 · Jun 12, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 28, 2026 · 7d agoAdvisory updatedThe NVD record was last revised.
- Jul 28, 2026 · 6d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- lists.apache.org/thread/3kb9w5bg90xcp06fccoz…vendor advisory
- openwall.com/lists/oss-security/2026/06/…mailing listthird party advisory
- access.redhat.com/errata/RHSA-2026:36839
- access.redhat.com/errata/RHSA-2026:37390
- access.redhat.com/security/cve/CVE-2026-49875
- bugzilla.redhat.com/show_bug.cgi
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2…