Junglewise Threat Intelligence

CVE-2026-44046: Apache APISIX identity spoofing in wolf-rbac plugin

CVE-2026-44046 · Severity: info · CVSS 2.3 · Published 2026-06-19

Technologies: Apache APISIX. Vendors: Apache.

Executive brief

Apache APISIX, a popular cloud-native API gateway, contains a security flaw in its wolf-rbac plugin. Under default configurations, an attacker can bypass certain IP-based access controls and inject false identity information into system logs. This could allow unauthorized access to protected resources or hinder forensic investigations by masking the attacker's true identity.

Technical details

A 'Use of Less Trusted Source' (CWE-348) vulnerability exists in the Apache APISIX wolf-rbac plugin. In default configurations, the plugin fails to properly validate or prioritize trusted sources for identity and IP information. A remote attacker with low privileges can exploit this to spoof identity data, leading to log pollution and the potential bypass of IP-based access control lists (ACLs). The vulnerability affects versions 1.2.0 through 3.16.0 and is resolved in version 3.17.0 (or 3.16.1 as noted in some advisory channels).

Affected products

  • Apache APISIX 1.2.0 through 3.16.0

Timeline

  • 2026-06-19: disclosed
  • 2026-06-19: advisory

References