---
cve: "CVE-2026-57818"
severity: "HIGH"
cvss: 8.1
epss: "34%"
vendor: "Apache Software Foundation"
kev: false
exploited: false
published: "2026-08-06 12:16:27"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-07T05:53:23+02:00"
---

# CVE-2026-57818

> 8.1 HIGH

## Beschreibung

A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization code multiple times via concurrent requests, resulting in the issuance of multiple distinct, valid access tokens. Users are recommended to upgrade to versions 4.2.3, 4.1.8 or 3.6.12, which fix this issue.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Hoch | good |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Patch verfügbar (OSV)

- 16d606b3c4d5c7d271fd3b488c60a208586acb3f (Commit)
- 8797a177ec23e9c578c78a630c154ad27d9bbe8d (Commit)

## Referenzen

- <https://lists.apache.org/thread/7q08mz8bcbosp25wok7gr537zlp15mfz>
- <http://www.openwall.com/lists/oss-security/2026/08/06/20>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-57818) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
