Improper Authentication Vulnerability in Apache APISIX by Apache
CVE-2026-49872

5.3MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
19 June 2026

What is CVE-2026-49872?

An improper authentication vulnerability has been identified in Apache APISIX, specifically when using the cas-auth plugin. This flaw allows potential attackers to authenticate themselves through credentials sourced from different systems, which could lead to unauthorized access. It affects versions from 3.0.0 to 3.16.0. Users are highly advised to upgrade to version 3.17.0, where this issue has been resolved, to ensure the security and integrity of their applications.

Affected Version(s)

Apache APISIX 3.0.0 <= 3.16.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

lokerxxx
.