CVE-2026-49231
published 2026-06-19CVE-2026-49231: Authentication Bypass by Spoofing vulnerability in opa plugin. An attacker could relay spoofed identity headers to upstream capitalising on non-default…
PriorityP337medium5.4CVSS 3.1
AVNACLPRLUINSUCLILAN
EPSS
0.36%
28.1th percentile
Authentication Bypass by Spoofing vulnerability in opa plugin.
An attacker could relay spoofed identity headers to upstream capitalising on non-default configuration in opa plugin.
This could allow the attacker to assume higher privileges on the upstream service.
This issue affects Apache APISIX: from 3.5.0 through 3.16.0.
Users are recommended to upgrade to version 3.17.0, which fixes the issue.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | apisix | >= 3.5.0 < 3.17.0 | 3.17.0 |
| apache_software_foundation | apache_apisix | 3.5.0 – 3.16.0 | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
nvdv4.02.3LOWCVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Authentication Bypass by Spoofing vulnerability in opa plugin.
ghsa_unreviewed·2026-06-19
CVE-2026-49231 [LOW] CWE-290 Authentication Bypass by Spoofing vulnerability in opa plugin.
Authentication Bypass by Spoofing vulnerability in opa plugin.
An attacker could relay spoofed identity headers to upstream capitalising on non-default configuration in opa plugin.
This could allow the attacker to assume higher privileges on the upstream service.
This issue affects Apache APISIX: from 3.5.0 through 3.16.0.
Users are recommended to upgrade to version 3.17.0, which fixes the issue.
VulDB
Apache APISIX up to 3.16.0 Upstream Service authentication spoofing (EUVD-2026-38020)
vuldb·2026-06-19
CVE-2026-49231 [CRITICAL] Apache APISIX up to 3.16.0 Upstream Service authentication spoofing (EUVD-2026-38020)
A vulnerability classified as critical was found in Apache APISIX up to 3.16.0. Affected by this vulnerability is an unknown functionality of the component Upstream Service. The manipulation results in authentication bypass by spoofing.
This vulnerability is reported as CVE-2026-49231. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-19
Published