Insufficient Data Authenticity Verification in Apache APISIX OpenID Connect Plugin
CVE-2026-44087
5.3MEDIUM
What is CVE-2026-44087?
The openid-connect plugin in Apache APISIX has a vulnerability that allows attackers to impersonate users by spoofing identity headers. This flaw can lead to unauthorized access to protected resources under default configurations. The issue impacts versions 2.3 through 3.16.0. Users are strongly encouraged to upgrade to version 3.17.0 to mitigate risks associated with this vulnerability.
Affected Version(s)
Apache APISIX 2.3 <= 3.16.0