CyberSec.Space Logo
CVEブラウザに戻る

CVE-2026-49871

CRITICAL
9.3
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2026-06-19
Last Modified2026-06-23
Data SourcesNVD

Vulnerability Description

Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin under default configurations. This defect allows a remote attacker that manages to send a victim to a webpage controlled by them can cause the victim's browser to become authenticated as a different identity. Actions the victim takes upstream are then attributed to attackers identity. This issue affects Apache APISIX: from 3.0.0 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue.

Affected Platforms (CPE)

No CPE configurations currently published for this record.

References & Advisories

関連する脆弱性情報