Database Management
Why SolarWinds Database Performance Analyzer is not affected by CVE-2026-50627, CVE-2026-50628, CVE-2026-66909, CVE-2026-65583, CVE-2026-63687 and CVE-2026-68079
This article explains why Database Performance Analyzer is not affected by the following Apache CVEs: CVE-2026-50627, CVE-2026-50628, CVE-2026-66909 CVE-2026-65583, CVE-2026-63687 and CVE-2026-68079.
First published date
Last published date
Overview
In 2026, the National Institute of Standards and Technology (NIST) published a security bulletin about the following CVEs:
NVD-CVE-2026-50627, NVD-CVE-2026-50628, NVD - CVE-2026-66909, NVD - CVE-2026-65583, NVD - CVE-2026-61466, NVD - CVE-2026-63687 and NVD-CVE-2026-68079.
Product section
Cause
CVE-2026-50627 is a Token Confusion/Routing vulnerability in Apache CXF. If exploited JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one Resource Server to be successfully replayed against a completely different Resource Server, leading to Token Confusion/Routing attacks.
CVE-2026-50628 is a logic vulnerability in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this security feature inadvertently creates an inverse security check.
CVE-2026-66909 is a Java deserialization vulnerability in Apache CXF. The Apache CXF JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the service's JMS destination can submit a malicious serialized object, leading to denial of service or, if a suitable gadget class is on the classpath, remote code execution. The fix disables ObjectMessage deserialization by default, with a configuration switch to re-enable it if needed.
CVE-2026-65583 The Apache CXF OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim checks (issuer/subject/audience/time and sub_jwk binding), enabling authentication bypass with crafted tokens. However, note that self-issued ID tokens are not accepted by default in the validator.
CVE-2026-61466 In the Apache CXF OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client registration request verbatim, without validating it against an AS-defined allowlist. This could lead to a client self-assigning privileged scopes at registration time.
CVE-2026-63687 is a sensitive information disclosure vulnerability in Apache CXF. The Apache CXF JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without excluding security-sensitive parameters. A client that can produce a validly-signed request JWT (e.g., one whose client_secret is known or compromised) can thereby substitute the code_challenge, code_challenge_method, nonce, and state values that were set in the outer HTTP request, undermining PKCE integrity and OpenID Connect replay protection.
CVE-2026-68079 is a broken access control vulnerability In Apache CXF. The Apache CXF DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the implementation of the removeCodeGrant functionality. This violates the RFC requirement that "The authorization code MUST NOT be used more than once."
Resolution
CVE-2026-50627: (False Positive) DPA does not use the Apache CXF JwtAccessTokenValidator class from the cxf-rt-rs-security-oauth2.jar library. Additionally, the cxf-rt-rs-security-oauth2 library is not used by DPA and is not packaged with the DPA application. Therefore, DPA is not affected by this vulnerability
CVE-2026-50628: (False Positive) DPA does not use the Apache CXF OAuthRequestFilter class from the cxf-rt-rs-security-oauth2.jar library. Additionally, the cxf-rt-rs-security-oauth2 library is not used by DPA and is not packaged with the DPA application. Therefore, DPA is not affected by this vulnerability.
CVE-2026-66909: (False Positive) DPA does not use the Apache CXF cxf-rt-transports-jms library, which is the affected component for CVE-2026-66909. The cxf-rt-transports-jms library is not included as a direct or transitive dependency and is therefore not packaged with the DPA application. As DPA does not use the affected Apache CXF JMS transport functionality, DPA is not affected by CVE-2026-66909.
CVE-2026-65583: (False Positive) DPA does not use the Apache CXF OIDC relying-party functionality provided by the cxf-rt-rs-security-sso-oidc library. The cxf-rt-rs-security-sso-oidc library is not used by DPA and is not packaged with the DPA application. Therefore, DPA is not affected by CVE-2026-65583.
CVE-2026-61466, CVE-2026-63687 & CVE-2026-68079: (False Positive) DPA does not use the Apache CXF OAuth2 functionality provided by the cxf-rt-rs-security-oauth2 library. The cxf-rt-rs-security-oauth2 library is not used by DPA and is not packaged with the DPA application. Therefore, DPA is not affected by these vulnerabilities.