
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-49231 is an Authentication Bypass by Spoofing vulnerability (CWE-290) in the Open Policy Agent (OPA) plugin of Apache APISIX. An attacker with low-level privileges can relay spoofed identity headers to upstream services when a non-default OPA plugin configuration is in use, potentially assuming higher privileges on those upstream services. The vulnerability affects Apache APISIX versions 3.5.0 through 3.16.0, and was publicly disclosed on June 18–19, 2026, with a fix available in version 3.17.0. It carries a CVSS v3.1 base score of 5.4 (Medium) and a CVSS v4.0 base score of 2.3 (Low) (Apache Advisory, GitHub Advisory).
The root cause is an improper authentication scheme in the Apache APISIX OPA plugin that fails to strip or validate identity headers before forwarding requests to upstream services under certain non-default configurations (CWE-290: Authentication Bypass by Spoofing). An attacker with low privileges can craft HTTP requests containing spoofed identity headers (e.g., user identity or role claims) that the OPA plugin does not sanitize, allowing those headers to be relayed to the upstream service as if they were legitimate. The precondition for exploitation is that the OPA plugin must be configured with a non-default setting that enables header relay behavior — deployments using only default configurations are not affected. The vulnerability was reported by researcher "lokerxxx" and disclosed via the Apache security mailing list and oss-security (oss-security, GitHub Advisory).
Successful exploitation allows an attacker to assume higher privileges on upstream services protected by the APISIX OPA plugin, resulting in low-level confidentiality and integrity impacts on those downstream systems. The vulnerable system itself (APISIX) does not suffer direct confidentiality, integrity, or availability loss, but subsequent systems receiving the spoofed headers may expose sensitive data or allow unauthorized actions. Availability is not impacted. The scope of impact is limited to environments using the non-default OPA plugin configuration, reducing the overall attack surface (GitHub Advisory, Apache Advisory).
There is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation as of the time of disclosure (GitHub Advisory). The EPSS score is approximately 0.355–0.36%, placing it in the 28th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. Exploitation requires low privileges and a specific non-default OPA plugin configuration, which limits the practical attack surface (GitHub Advisory, oss-security).
X-User, X-Role, or similar headers expected by the upstream service) that claim elevated privileges or a different user identity.X-User, X-Role, X-Identity, or custom headers defined by the upstream service) from low-privilege or unexpected source IPs.Users are strongly recommended to upgrade Apache APISIX to version 3.17.0 or later, which resolves the header relay issue in the OPA plugin (Apache Advisory, oss-security). As an interim workaround, administrators should review OPA plugin configurations and revert any non-default settings that enable identity header forwarding to upstream services. Additionally, implementing network-level controls to strip or validate identity headers at the perimeter before they reach APISIX can reduce exposure.
The vulnerability was disclosed by Apache via their security mailing list and the oss-security list on June 18–19, 2026, with credit given to reporter "lokerxxx" (oss-security). The advisory was noted on Bluesky by infosec community accounts shortly after disclosure. Overall community reaction has been measured, reflecting the moderate severity and limited exploitation conditions of the vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."