CVE-2026-49872
published 2026-06-19CVE-2026-49872: Improper Authentication vulnerability in Apache APISIX. When the cas-auth plugin is used in a route, an attacker can possibly authenticate itself with…
PriorityP354high8.1CVSS 3.1
AVNACLPRLUINSUCHIHAN
EPSS
0.32%
23.9th percentile
Improper Authentication vulnerability in Apache APISIX.
When the cas-auth plugin is used in a route, an attacker can possibly authenticate itself with credentials from a different source.
This issue affects Apache APISIX: from 3.0.0 through 3.16.0.
Users are recommended to upgrade to version 3.17.0, which fixes the issue.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | apisix | >= 3.0.0 < 3.17.0 | 3.17.0 |
| apache_software_foundation | apache_apisix | 3.0.0 – 3.16.0 | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
nvdv4.05.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apache APISIX up to 3.16.0 improper authentication (EUVD-2026-38026)
vuldb·2026-06-25·CVSS 8.1
CVE-2026-49872 [HIGH] Apache APISIX up to 3.16.0 improper authentication (EUVD-2026-38026)
A vulnerability has been found in Apache APISIX up to 3.16.0 and classified as critical. Affected by this vulnerability is an unknown functionality. This manipulation causes improper authentication.
This vulnerability is handled as CVE-2026-49872. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.
GHSA
Improper Authentication vulnerability in Apache APISIX.
ghsa_unreviewed·2026-06-19
CVE-2026-49872 [MEDIUM] CWE-287 Improper Authentication vulnerability in Apache APISIX.
Improper Authentication vulnerability in Apache APISIX.
When the cas-auth plugin is used in a route, an attacker can possibly authenticate itself with credentials from a different source.
This issue affects Apache APISIX: from 3.0.0 through 3.16.0.
Users are recommended to upgrade to version 3.17.0, which fixes the issue.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-19
Published