Authorization Vulnerability in Apache APISIX by Apache Software Foundation
CVE-2026-94269

6.3MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
1 October 2026

What is CVE-2026-94269?

A vulnerability exists within Apache APISIX regarding the use of non-canonical URL paths for authorization decisions. This flaw emerges in scenarios where a permissive route inadvertently overlaps a protected route. Consequently, a specially crafted encoded path could access an upstream endpoint, enabling unauthenticated utilization of resources that should remain secure. It is crucial for users of Apache APISIX versions 2.14.1 through 3.18.0 to upgrade to version 3.19.0 to mitigate this vulnerability.

Affected Version(s)

Apache APISIX 2.14.1 <= 3.18.0

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ziyue
shreemaan-abhishek
shreemaan-abhishek
.