Improper Authentication Vulnerability in Apache APISIX by Apache
CVE-2026-94276

5.1MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
1 October 2026

What is CVE-2026-94276?

An improper authentication vulnerability exists in Apache APISIX affecting versions 3.12.0 through 3.18.0. This issue arises within routes utilizing the openid-connect plugin when performing remote introspection against an authorization server that serves multiple issuers. Specifically, a token that verifies as active for one issuer may be incorrectly accepted on routes intended to restrict access to a different issuer. To mitigate this vulnerability, users are advised to upgrade their systems to version 3.19.0 or newer.

Affected Version(s)

Apache APISIX 3.12.0 <= 3.18.0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

sec-reex
shreemaan-abhishek
shreemaan-abhishek
.