Apache Software FoundationCVE-2026-94276
Apache APISIX: improper authentication
Medium5.1CVE-2026-94276 · Published Oct 1, 2026
Improper Authentication vulnerability in Apache APISIX. On a route using openid-connect plugin with remote introspection against an authorization server that serves multiple issuers, a token that introspects as active for one issuer may get accepted on a route restricted to another. This issue affects Apache APISIX: from 3.12.0 through 3.18.0. Users are recommended to upgrade to version 3.19.0, which fixes the issue.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Apache APISIX Product | >= 3.12.0, <= 3.18.0 | No fix yet |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-287
More Apache Software Foundation advisories
All Apache Software Foundation| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 1 | Apache HTTP Server: integer overflow | High8.8 | No fix yet |
| Oct 1 | Apache HTTP Server: use after free | High7.3 | No fix yet |
| Oct 1 | Path equivalence: '/./' | Medium5.3 | No fix yet |
| Oct 1 | Apache HTTP Server: request smuggling | High7.5 | No fix yet |
| Oct 1 | Apache HTTP Server: authentication bypass | High8.1 | No fix yet |
| Oct 1 | Apache HTTP Server: exposed files | Medium5.3 | No fix yet |