Authentication Bypass Vulnerability in Apache APISIX
CVE-2026-47341
6.3MEDIUM
What is CVE-2026-47341?
An authentication bypass vulnerability has been identified in Apache APISIX, where certain configurations of hmac-auth allow an attacker to reuse a valid token indefinitely, circumventing the intended expiration mechanism. This security issue affects versions 3.11.0 through 3.16.0, underscoring the importance of applying the latest patch by upgrading to version 3.17.0 to safeguard against potential exploitation.
Affected Version(s)
Apache APISIX 3.11.0 <= 3.16.0