
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-49872 is an Improper Authentication vulnerability (CWE-287) in Apache APISIX's cas-auth plugin that allows an attacker with low-level credentials to authenticate using credentials from a different, unintended source, effectively bypassing route-level access controls. It affects Apache APISIX versions 3.0.0 through 3.16.0 and was publicly disclosed on June 18–19, 2026, with a fix released in version 3.17.0. The vulnerability carries a CVSS v3.1 base score of 8.1 (High) and a CVSS v4.0 base score of 5.3 (Medium) (Apache Advisory, GitHub Advisory).
The root cause is improper authentication logic (CWE-287) in the cas-auth plugin, which fails to adequately validate that the credentials presented during authentication originate from the expected CAS (Central Authentication Service) source for the configured route. An attacker who possesses valid credentials from an alternative authentication source can supply those credentials to a route protected by the cas-auth plugin, and APISIX will incorrectly accept them as legitimate. Exploitation requires network access and low-level privileges (e.g., credentials from another source), but no user interaction. The vulnerability was reported by researcher "lokerxxx" and disclosed via the Apache oss-security mailing list (oss-security, GitHub Advisory).
Successful exploitation allows an attacker to bypass authentication controls on routes protected by the cas-auth plugin, gaining unauthorized access to backend services or APIs proxied through Apache APISIX. The primary impacts are high confidentiality and high integrity compromise of downstream (subsequent) systems, as an attacker can access and potentially manipulate data or services that should be restricted. Availability is not directly impacted. The scope of exposure depends on what backend services are protected by affected routes, and could facilitate lateral movement into internal systems if APISIX acts as an API gateway to sensitive infrastructure (Apache Advisory, GitHub Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.33%, placing it in the 24th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. NVD's SSVC assessment classifies exploitation as "none" and the attack as non-automatable, reflecting the requirement for an attacker to already possess credentials from an alternative source (GitHub Advisory).
cas-auth plugin. Tools like Shodan or Censys can be used to locate APISIX API gateways.cas-auth, supplying the credentials from the alternative source rather than the expected source.cas-auth plugin, APISIX accepts the alternative credentials as valid, granting access to the protected route and its backend services.cas-auth originating from unusual IP addresses or geographic locations; successful authentication events using credentials not associated with the expected CAS identity provider.200 OK responses on cas-auth-protected routes from users or sessions that do not correspond to expected CAS service ticket sources; authentication events with mismatched CAS service URLs or ticket origins.The primary remediation is to upgrade Apache APISIX to version 3.17.0 or later, which contains the fix for this vulnerability (Apache Advisory). If an immediate upgrade is not feasible, organizations should review all routes using the cas-auth plugin and consider restricting them to non-critical services, implementing additional authentication layers (e.g., IP allowlisting, mTLS), or applying network-level access controls to limit who can reach those routes. Monitoring APISIX authentication logs for anomalous credential sources is also recommended as a compensating control.
The vulnerability was disclosed via the Apache security mailing list and oss-security by Abhishek Choudhary on behalf of the Apache APISIX team, crediting reporter "lokerxxx" (oss-security). A brief post on Bluesky from the infosec community noted the advisory shortly after publication. Coverage has been limited to automated vulnerability tracking platforms and aggregators, with no major media coverage or significant researcher commentary observed at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."