Less Trusted Source Vulnerability in Apache APISIX by Apache
CVE-2026-44046
2.3LOW
What is CVE-2026-44046?
A vulnerability in Apache APISIX manifests through the wolf-rbac plugin, allowing attackers to potentially manipulate logs with spoofed identity data and exploit IP-based access control measures under default configurations. This affects versions 1.2.0 through 3.16.0, and users are advised to upgrade to version 3.17.0 to effectively address the issue.
Affected Version(s)
Apache APISIX 1.2.0 <= 3.16.0