Incorrect Authorization Vulnerability in Apache APISIX by Apache
CVE-2026-47339
5.3MEDIUM
What is CVE-2026-47339?
An incorrect authorization vulnerability exists in Apache APISIX, specifically within the authz-casdoor plugin. This vulnerability allows an attacker to authenticate using credentials sourced from a different entity if the plugin is configured with default settings. This affects multiple versions of Apache APISIX, rendering them susceptible to unauthorized access. Users are strongly advised to upgrade to version 3.17.0 or later to remediate this issue and enhance security.
Affected Version(s)
Apache APISIX 2.14.1 <= 3.16.0