CVE-2026-49872
Apache APISIX vulnerability analysis and mitigation

Overview

CVE-2026-49872 is an Improper Authentication vulnerability (CWE-287) in Apache APISIX's cas-auth plugin that allows an attacker with low-level credentials to authenticate using credentials from a different, unintended source, effectively bypassing route-level access controls. It affects Apache APISIX versions 3.0.0 through 3.16.0 and was publicly disclosed on June 18–19, 2026, with a fix released in version 3.17.0. The vulnerability carries a CVSS v3.1 base score of 8.1 (High) and a CVSS v4.0 base score of 5.3 (Medium) (Apache Advisory, GitHub Advisory).

Technical details

The root cause is improper authentication logic (CWE-287) in the cas-auth plugin, which fails to adequately validate that the credentials presented during authentication originate from the expected CAS (Central Authentication Service) source for the configured route. An attacker who possesses valid credentials from an alternative authentication source can supply those credentials to a route protected by the cas-auth plugin, and APISIX will incorrectly accept them as legitimate. Exploitation requires network access and low-level privileges (e.g., credentials from another source), but no user interaction. The vulnerability was reported by researcher "lokerxxx" and disclosed via the Apache oss-security mailing list (oss-security, GitHub Advisory).

Impact

Successful exploitation allows an attacker to bypass authentication controls on routes protected by the cas-auth plugin, gaining unauthorized access to backend services or APIs proxied through Apache APISIX. The primary impacts are high confidentiality and high integrity compromise of downstream (subsequent) systems, as an attacker can access and potentially manipulate data or services that should be restricted. Availability is not directly impacted. The scope of exposure depends on what backend services are protected by affected routes, and could facilitate lateral movement into internal systems if APISIX acts as an API gateway to sensitive infrastructure (Apache Advisory, GitHub Advisory).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.33%, placing it in the 24th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. NVD's SSVC assessment classifies exploitation as "none" and the attack as non-automatable, reflecting the requirement for an attacker to already possess credentials from an alternative source (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify Apache APISIX instances (versions 3.0.0–3.16.0) exposed to the network, particularly those with routes configured to use the cas-auth plugin. Tools like Shodan or Censys can be used to locate APISIX API gateways.
  2. Obtain alternative credentials: Acquire valid credentials from a CAS-compatible authentication source that is different from the one intended for the target route (e.g., credentials from another CAS realm or tenant).
  3. Craft authentication request: Send an authentication request to the APISIX route protected by cas-auth, supplying the credentials from the alternative source rather than the expected source.
  4. Bypass authentication: Due to the improper validation in the cas-auth plugin, APISIX accepts the alternative credentials as valid, granting access to the protected route and its backend services.
  5. Access backend resources: Use the authenticated session to interact with the backend API or service, potentially exfiltrating data or performing unauthorized actions (oss-security, Apache Advisory).

Indicators of compromise

  • Network: Unexpected authentication requests to APISIX routes protected by cas-auth originating from unusual IP addresses or geographic locations; successful authentication events using credentials not associated with the expected CAS identity provider.
  • Logs: APISIX access logs showing successful 200 OK responses on cas-auth-protected routes from users or sessions that do not correspond to expected CAS service ticket sources; authentication events with mismatched CAS service URLs or ticket origins.
  • Application: Anomalous user sessions accessing backend services through APISIX that do not match expected user identity patterns; access to sensitive API endpoints by accounts not provisioned for those routes.

Mitigation and workarounds

The primary remediation is to upgrade Apache APISIX to version 3.17.0 or later, which contains the fix for this vulnerability (Apache Advisory). If an immediate upgrade is not feasible, organizations should review all routes using the cas-auth plugin and consider restricting them to non-critical services, implementing additional authentication layers (e.g., IP allowlisting, mTLS), or applying network-level access controls to limit who can reach those routes. Monitoring APISIX authentication logs for anomalous credential sources is also recommended as a compensating control.

Community reactions

The vulnerability was disclosed via the Apache security mailing list and oss-security by Abhishek Choudhary on behalf of the Apache APISIX team, crediting reporter "lokerxxx" (oss-security). A brief post on Bluesky from the infosec community noted the advisory shortly after publication. Coverage has been limited to automated vulnerability tracking platforms and aggregators, with no major media coverage or significant researcher commentary observed at this time.

Additional resources


SourceThis report was generated using AI

Related Apache APISIX vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-49230MEDIUM6.3
  • Apache APISIX logoApache APISIX
  • cpe:2.3:a:apache:apisix
NoYesJun 19, 2026
CVE-2026-49872MEDIUM5.3
  • Apache APISIX logoApache APISIX
  • apache-apisix
NoYesJun 19, 2026
CVE-2026-49231LOW2.3
  • Apache APISIX logoApache APISIX
  • apache-apisix
NoYesJun 19, 2026
CVE-2026-49871LOW2.1
  • Apache APISIX logoApache APISIX
  • cpe:2.3:a:apache:apisix
NoYesJun 19, 2026
CVE-2026-48895LOW2.1
  • Apache APISIX logoApache APISIX
  • cpe:2.3:a:apache:apisix
NoYesJun 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management