---
id: CVE-2026-50632
title: "A further incomplete fix for\_a previous advisory CVE-2026-44417\_(Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JM…"
summary: "A further incomplete fix for\_a previous advisory CVE-2026-44417\_(Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JM…"
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-20
  - CWE-502
vendor: apache
product: cxf
affected:
  - cxf < 4.1.7
  - 'cxf >= 4.2.0, < 4.2.2'
patched:
  - cxf 4.2.2
published: '2026-06-12'
updated: '2026-08-07'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-50632'
references:
  - url: 'https://lists.apache.org/thread/740ghch5z5y675cn2kzgtyo5k37n6qcw'
    label: security@apache.org
  - url: 'https://access.redhat.com/errata/RHSA-2026:37390'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-50632'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2488304'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50632.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-50632'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-50632'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70230'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70228'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70229'
tags:
  - nvd
  - csaf
  - vex
  - red-hat
epss: 0.01116
epssPercentile: 0.64716
ingestedAt: '2026-08-07T14:14:17.509Z'
scores:
  nvd: 8.1
  vendor: 8.8
---

## Overview

A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fixes this issue.

## Affected

- `cxf < 4.1.7`
- `cxf >= 4.2.0, < 4.2.2`

## Remediation

Upgrade past the affected range:

- `cxf 4.2.2`

## Vendor advisories

- **RHSA-2026:70230** · Red Hat · fixed in: Red Hat JBoss EAP 8.1 for RHEL 10 · released 2026-09-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:70230)
- **RHSA-2026:70228** · Red Hat · fixed in: Red Hat JBoss EAP 8.1 for RHEL 8 · released 2026-09-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:70228)
- **RHSA-2026:70229** · Red Hat · fixed in: Red Hat JBoss EAP 8.1 for RHEL 9 · released 2026-09-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:70229)
- **RHSA-2026:37390** · Red Hat · fixed in: Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16 · released 2026-07-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:37390)
- **Red Hat VEX** · Important · affected: Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7, Red Hat Single Sign-On 7 · no fix planned: Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7, Red Hat Single Sign-On 7 · updated 2026-09-22 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50632.json)
