{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Important"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright © Red Hat, Inc. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50632.json"
      }
    ],
    "title": "cxf: org.apache.cxf/cxf-rt-transports-jms: Apache CXF: Arbitrary code execution via untrusted JMS configuration",
    "tracking": {
      "current_release_date": "2026-07-09T15:31:06+00:00",
      "generator": {
        "date": "2026-07-09T15:31:06+00:00",
        "engine": {
          "name": "Red Hat SDEngine",
          "version": "5.3.2"
        }
      },
      "id": "CVE-2026-50632",
      "initial_release_date": "2026-06-12T09:00:48.530000+00:00",
      "revision_history": [
        {
          "date": "2026-06-12T09:00:48.530000+00:00",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-06-17T10:36:08.457671+00:00",
          "number": "2",
          "summary": "Current version"
        },
        {
          "date": "2026-07-09T15:31:06+00:00",
          "number": "3",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "3"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Fuse 7",
                "product": {
                  "name": "Red Hat Fuse 7",
                  "product_id": "red_hat_fuse_7",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:jboss_fuse:7"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Fuse 7"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat JBoss Enterprise Application Platform 7",
                "product": {
                  "name": "Red Hat JBoss Enterprise Application Platform 7",
                  "product_id": "red_hat_jboss_enterprise_application_platform_7",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat JBoss Enterprise Application Platform 7"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat JBoss Enterprise Application Platform 8",
                "product": {
                  "name": "Red Hat JBoss Enterprise Application Platform 8",
                  "product_id": "red_hat_jboss_enterprise_application_platform_8",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:8"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat JBoss Enterprise Application Platform 8"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat JBoss Enterprise Application Platform Expansion Pack",
                "product": {
                  "name": "Red Hat JBoss Enterprise Application Platform Expansion Pack",
                  "product_id": "red_hat_jboss_enterprise_application_platform_expansion_pack",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:jbosseapxp"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat JBoss Enterprise Application Platform Expansion Pack"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Single Sign-On 7",
                "product": {
                  "name": "Red Hat Single Sign-On 7",
                  "product_id": "red_hat_single_sign-on_7",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:red_hat_single_sign_on:7"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Single Sign-On 7"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16",
                "product": {
                  "name": "Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16",
                  "product_id": "Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:apache_camel_spring_boot:4.18"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Build of Apache Camel"
          },
          {
            "category": "product_version",
            "name": "cxf-rt-transports-jms",
            "product": {
              "name": "cxf-rt-transports-jms",
              "product_id": "cxf-rt-transports-jms",
              "product_identification_helper": {
                "purl": "pkg:maven/org.apache.cxf/cxf-rt-transports-jms"
              }
            }
          }
        ],
        "category": "vendor",
        "name": "Red Hat"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "cxf-rt-transports-jms as a component of Red Hat Fuse 7",
          "product_id": "red_hat_fuse_7:cxf-rt-transports-jms"
        },
        "product_reference": "cxf-rt-transports-jms",
        "relates_to_product_reference": "red_hat_fuse_7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "cxf-rt-transports-jms as a component of Red Hat JBoss Enterprise Application Platform 7",
          "product_id": "red_hat_jboss_enterprise_application_platform_7:cxf-rt-transports-jms"
        },
        "product_reference": "cxf-rt-transports-jms",
        "relates_to_product_reference": "red_hat_jboss_enterprise_application_platform_7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "cxf-rt-transports-jms as a component of Red Hat JBoss Enterprise Application Platform 8",
          "product_id": "red_hat_jboss_enterprise_application_platform_8:cxf-rt-transports-jms"
        },
        "product_reference": "cxf-rt-transports-jms",
        "relates_to_product_reference": "red_hat_jboss_enterprise_application_platform_8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "cxf-rt-transports-jms as a component of Red Hat JBoss Enterprise Application Platform Expansion Pack",
          "product_id": "red_hat_jboss_enterprise_application_platform_expansion_pack:cxf-rt-transports-jms"
        },
        "product_reference": "cxf-rt-transports-jms",
        "relates_to_product_reference": "red_hat_jboss_enterprise_application_platform_expansion_pack"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "cxf-rt-transports-jms as a component of Red Hat Single Sign-On 7",
          "product_id": "red_hat_single_sign-on_7:cxf-rt-transports-jms"
        },
        "product_reference": "cxf-rt-transports-jms",
        "relates_to_product_reference": "red_hat_single_sign-on_7"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-50632",
      "cwe": {
        "id": "CWE-502",
        "name": "Deserialization of Untrusted Data"
      },
      "discovery_date": "2026-06-12T10:01:09.993388+00:00",
      "flags": [
        {
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "red_hat_jboss_enterprise_application_platform_expansion_pack:cxf-rt-transports-jms"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2488304"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in Apache CXF. This vulnerability, stemming from an incomplete fix for a previous issue, allows untrusted users who can configure Java Message Service (JMS) for Apache CXF to achieve arbitrary code execution. This could lead to a complete compromise of the affected system.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "cxf: org.apache.cxf/cxf-rt-transports-jms: Apache CXF: Arbitrary code execution via untrusted JMS configuration",
          "title": "Vulnerability summary"
        },
        {
          "category": "other",
          "text": "This Important flaw in Apache CXF's JMS transport allows arbitrary code execution. The vulnerability occurs when untrusted users can configure Java Message Service (JMS) for Apache CXF, potentially leading to a complete system compromise. This risk is present in environments where JMS configuration is accessible to or managed by untrusted entities.",
          "title": "Statement"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16"
        ],
        "known_affected": [
          "red_hat_fuse_7:cxf-rt-transports-jms",
          "red_hat_jboss_enterprise_application_platform_7:cxf-rt-transports-jms",
          "red_hat_jboss_enterprise_application_platform_8:cxf-rt-transports-jms",
          "red_hat_single_sign-on_7:cxf-rt-transports-jms"
        ],
        "known_not_affected": [
          "red_hat_jboss_enterprise_application_platform_expansion_pack:cxf-rt-transports-jms"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-50632"
        },
        {
          "category": "external",
          "summary": "RHBZ#2488304",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2488304"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-50632",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-50632"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-50632",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50632"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/740ghch5z5y675cn2kzgtyo5k37n6qcw",
          "url": "https://lists.apache.org/thread/740ghch5z5y675cn2kzgtyo5k37n6qcw"
        }
      ],
      "release_date": "2026-06-12T09:00:48.530000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-07-09T15:29:15+00:00",
          "details": "Before applying this update, make sure all previously released errata\nrelevant to your system have been applied.\n\nFor details on how to apply this update, refer to:\n\nhttps://access.redhat.com/articles/11258",
          "product_ids": [
            "Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16"
          ],
          "url": "https://access.redhat.com/errata/RHSA-2026:37390"
        },
        {
          "category": "workaround",
          "details": "To mitigate this issue, ensure that only trusted administrators have the necessary permissions to configure Java Message Service (JMS) for Apache CXF. Restricting access to JMS configuration prevents untrusted users from exploiting this vulnerability. Review and enforce strict access controls on systems where Apache CXF is deployed with JMS transport.",
          "product_ids": [
            "Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16",
            "red_hat_fuse_7:cxf-rt-transports-jms",
            "red_hat_jboss_enterprise_application_platform_7:cxf-rt-transports-jms",
            "red_hat_jboss_enterprise_application_platform_8:cxf-rt-transports-jms",
            "red_hat_single_sign-on_7:cxf-rt-transports-jms"
          ]
        },
        {
          "category": "none_available",
          "details": "Fix deferred",
          "product_ids": [
            "red_hat_fuse_7:cxf-rt-transports-jms",
            "red_hat_jboss_enterprise_application_platform_7:cxf-rt-transports-jms",
            "red_hat_single_sign-on_7:cxf-rt-transports-jms"
          ]
        },
        {
          "category": "none_available",
          "details": "Affected",
          "product_ids": [
            "red_hat_jboss_enterprise_application_platform_8:cxf-rt-transports-jms"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16",
            "red_hat_fuse_7:cxf-rt-transports-jms",
            "red_hat_jboss_enterprise_application_platform_7:cxf-rt-transports-jms",
            "red_hat_jboss_enterprise_application_platform_8:cxf-rt-transports-jms",
            "red_hat_jboss_enterprise_application_platform_expansion_pack:cxf-rt-transports-jms",
            "red_hat_single_sign-on_7:cxf-rt-transports-jms"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important",
          "product_ids": [
            "Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16",
            "red_hat_fuse_7:cxf-rt-transports-jms",
            "red_hat_jboss_enterprise_application_platform_7:cxf-rt-transports-jms",
            "red_hat_jboss_enterprise_application_platform_8:cxf-rt-transports-jms",
            "red_hat_jboss_enterprise_application_platform_expansion_pack:cxf-rt-transports-jms",
            "red_hat_single_sign-on_7:cxf-rt-transports-jms"
          ]
        }
      ],
      "title": "cxf: org.apache.cxf/cxf-rt-transports-jms: Apache CXF: Arbitrary code execution via untrusted JMS configuration"
    }
  ]
}