Insufficient Data Authenticity Verification in Apache APISIX OpenID Connect Plugin
CVE-2026-44087

5.3MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
19 June 2026

What is CVE-2026-44087?

The openid-connect plugin in Apache APISIX has a vulnerability that allows attackers to impersonate users by spoofing identity headers. This flaw can lead to unauthorized access to protected resources under default configurations. The issue impacts versions 2.3 through 3.16.0. Users are strongly encouraged to upgrade to version 3.17.0 to mitigate risks associated with this vulnerability.

Affected Version(s)

Apache APISIX 2.3 <= 3.16.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Qi Deng
.