
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-49871 is a Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin of Apache APISIX under default configurations. A remote attacker who can direct a victim to an attacker-controlled webpage can cause the victim's browser to become authenticated as a different identity, with subsequent actions attributed to the attacker's chosen identity. The vulnerability affects Apache APISIX versions 3.0.0 through 3.16.0 and was publicly disclosed on June 18–19, 2026. It carries a CVSS v3.1 base score of 9.3 (Critical) and a CVSS v4.0 base score of 2.1 (Low), reflecting differing scoring methodologies (Apache Advisory, GitHub Advisory).
The root cause is classified as CWE-352 (Cross-Site Request Forgery), where the cas-auth plugin in Apache APISIX fails to sufficiently verify that authentication requests were intentionally initiated by the legitimate user. Under default configurations, the CAS (Central Authentication Service) login flow does not implement adequate CSRF protections, allowing an attacker to craft a malicious webpage that triggers the victim's browser to complete an authentication handshake as an attacker-chosen identity. Exploitation requires no privileges and no special attack complexity, but does require user interaction (the victim visiting the attacker's page) and the presence of specific deployment conditions (Attack Requirements: Present in CVSS v4.0). No public proof-of-concept exploit code has been identified at this time (Apache Advisory, oss-security).
Successful exploitation allows an unauthenticated remote attacker to cause a victim's session to be authenticated under an attacker-controlled identity, effectively performing session injection or authentication bypass. Actions subsequently taken by the victim within the APISIX-protected application are attributed to the attacker's identity, enabling unauthorized access, privilege abuse, and potential data manipulation. The impact is primarily on integrity and confidentiality of downstream systems accessed through the gateway, with no direct availability impact (GitHub Advisory, Apache Advisory).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.23–0.26%, placing it in the 17th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. The vulnerability was reported by researcher "lokerxxx" and disclosed through Apache's security advisory process (oss-security, GitHub Advisory).
cas-auth plugin enabled, using network scanning or public exposure discovery tools./apisix/plugin/cas-auth/callback or equivalent) originating from unexpected referrers or with mismatched session/identity parameters; repeated authentication events for the same session from different identities.Users should upgrade Apache APISIX to version 3.17.0, which contains the official fix for this vulnerability (Apache Advisory). For deployments unable to upgrade immediately, administrators should review and harden the cas-auth plugin configuration to add explicit CSRF token validation, configure SameSite=Strict or SameSite=Lax cookie attributes, and implement Content Security Policy (CSP) headers to restrict cross-origin requests. Additionally, network-level controls such as restricting access to the CAS callback endpoint to known trusted origins can reduce exposure.
The vulnerability was disclosed via the Apache security mailing list and oss-security on June 18–19, 2026, with credit given to reporter "lokerxxx" (oss-security). Social media activity was limited, with brief mentions on Bluesky and Mastodon/infosec.exchange by automated vulnerability tracking accounts. No significant vendor statements beyond the official advisory or notable independent researcher commentary have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."