CVE-2026-50628

EUVD-2026-36396
A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this

security feature inadvertently creates an inverse security check. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 49%
Affected Products (NVD)
VendorProductVersion
apachecxf
𝑥
< 4.1.7
apachecxf
4.2.0 ≤
𝑥
< 4.2.2
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
Red HatRed Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16
security-oauth2 ≤
𝑥
< *
ADP
Red HatRed Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16
oauth2-saml ≤
𝑥
< *
ADP