CVE-2026-61466
CVE-2026-61466: 2 tracked advisory records across Apache, NetApp. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Apache
1 advisory- Advisory severityCritical9.1
Critical [CVE-2026-61466] In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client registration request verbatim, without validating it against an AS-defined allowlist
CVE-2026-61466Source published Source updated
In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client registration request verbatim, without validating it against an AS-defined allowlist. This could lead to a client self-assigning privileged scopes at registration time. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
- Affected products in this advisory
- Apache CXF
- Source-reported affected versions
- Apache CXF before 3.6.12
- Apache CXF 4.0.0 before 4.1.8
- Apache CXF 4.2.0 before 4.2.3
- Source-reported fixed versions
- 4.2.3
- 4.1.8
- 3.6.12
- Mitigation guidance
- Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
NetApp
1 advisory- Advisory severityCritical9.1
Critical [CVE-2026-61466] Apache CXF Vulnerability in NetApp Products
NTAP-20260911-0003Source published Source updated
Apache CXF versions prior to 3.6.12, 4.0.0 prior to 4.1.8, and 4.2.0 prior to 4.2.3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
- Affected products in this advisory
- No product details extracted. Check the source bulletin.
- Source-reported affected versions
- 3.6.12
- 4.0.0
- 4.1.8
- 4.2.0
1 more entries in the full advisory.
- Source-reported fixed versions
- No fixed-version detail extracted. This does not mean no fix exists.
- Mitigation guidance
- No mitigation guidance extracted; consult the source.
Android app · Google Play
Turn CVE research into alerts on your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.