CyberSec.Space Logo
Back to CVE Browser

CVE-2026-49231

MEDIUM
5.4
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2026-06-19
Last Modified2026-06-23
Data SourcesNVD

Vulnerability Description

Authentication Bypass by Spoofing vulnerability in opa plugin. An attacker could relay spoofed identity headers to upstream capitalising on non-default configuration in opa plugin. This could allow the attacker to assume higher privileges on the upstream service. This issue affects Apache APISIX: from 3.5.0 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue.

Affected Platforms (CPE)

No CPE configurations currently published for this record.

References & Advisories

Related Vulnerabilities