Junglewise Threat Intelligence

CVE-2026-44087: Apache APISIX identity header spoofing in openid-connect plugin

CVE-2026-44087 · Severity: info · CVSS 5.3 · Published 2026-06-19

Technologies: Apache APISIX. Vendors: Apache.

Executive brief

Apache APISIX, a popular cloud-native API gateway, contains a security flaw in its OpenID Connect plugin. Under default configurations, an attacker can forge identity information to bypass security checks. This could allow unauthorized individuals to access protected internal resources or sensitive customer data.

Technical details

An Insufficient Verification of Data Authenticity vulnerability (CWE-345) exists in the Apache APISIX openid-connect plugin. Under default configurations, the plugin fails to properly validate identity headers, creating an attack surface for header spoofing. A remote attacker with low privileges can exploit this to bypass authentication mechanisms and gain unauthorized access to upstream resources. The issue affects versions 2.3 through 3.16.0 and is resolved in version 3.17.0 (or 3.16.1 as per some advisory notes).

Affected products

  • Apache APISIX 2.3 through 3.16.0

Timeline

  • 2026-06-19: disclosed
  • 2026-06-19: advisory

References

Related threats