Authorization Vulnerability in Apache APISIX by Apache Software Foundation
CVE-2026-94269
6.3MEDIUM
What is CVE-2026-94269?
A vulnerability exists within Apache APISIX regarding the use of non-canonical URL paths for authorization decisions. This flaw emerges in scenarios where a permissive route inadvertently overlaps a protected route. Consequently, a specially crafted encoded path could access an upstream endpoint, enabling unauthenticated utilization of resources that should remain secure. It is crucial for users of Apache APISIX versions 2.14.1 through 3.18.0 to upgrade to version 3.19.0 to mitigate this vulnerability.
Affected Version(s)
Apache APISIX 2.14.1 <= 3.18.0
References
CVSS V4
Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ziyue
shreemaan-abhishek
shreemaan-abhishek