Improper Authentication Vulnerability in Apache APISIX by Apache
CVE-2026-94276
5.1MEDIUM
What is CVE-2026-94276?
An improper authentication vulnerability exists in Apache APISIX affecting versions 3.12.0 through 3.18.0. This issue arises within routes utilizing the openid-connect plugin when performing remote introspection against an authorization server that serves multiple issuers. Specifically, a token that verifies as active for one issuer may be incorrectly accepted on routes intended to restrict access to a different issuer. To mitigate this vulnerability, users are advised to upgrade their systems to version 3.19.0 or newer.
Affected Version(s)
Apache APISIX 3.12.0 <= 3.18.0
References
CVSS V4
Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
sec-reex
shreemaan-abhishek
shreemaan-abhishek