PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-49875 Apache Software Foundation CVE debrief

CVE-2026-49875 is a vulnerability in Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes. These classes construct a SAXParserFactory without the necessary JAXP hardening configurations, which enables out-of-band (OOB) external entity resolution. This vulnerability was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-49875) and last modified on [cveModifiedAt](https://nvd.nist.gov/vuln/detail/CVE-2026-49875).

Vendor
Apache Software Foundation
Product
Apache CXF
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-12
Original CVE updated
2026-06-12
Advisory published
2026-06-12
Advisory updated
2026-06-12

Who should care

Users of Apache CXF are recommended to upgrade to versions 4.2.2 or 4.1.7, which fix this issue.

Technical summary

Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution.

Defensive priority

high

Recommended defensive actions

  • Upgrade to Apache CXF version 4.2.2 or 4.1.7.

Evidence notes

The CVE was published on [resourceLinkAnnotations:cve-org] and additional details can be found on [resourceLinkAnnotations:nvd].

Official resources

CVE-2026-49875 was published on June 12, 2026, and last modified on June 12, 2026.