Junglewise Threat Intelligence

CVE-2026-47339: Apache APISIX incorrect authorization in authz-casdoor plugin

CVE-2026-47339 · Severity: info · CVSS 5.3 · Published 2026-06-19

Technologies: Apache APISIX. Vendors: Apache.

Executive brief

Apache APISIX is a cloud-native API gateway used to manage and secure network traffic between clients and services. A security flaw in its Casdoor authentication plugin allows an attacker to bypass intended security checks by using credentials from an unauthorized source. This could allow unauthorized users to gain access to protected systems or data, potentially leading to a breach of sensitive internal resources.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in the authz-casdoor plugin of Apache APISIX. When running under default configurations, the plugin fails to properly validate the source of authentication credentials, leading to a form of incorrect session sharing or credential cross-contamination. A remote attacker with low privileges can exploit this to authenticate themselves using credentials from a different source than intended. The vulnerability affects versions 2.14.1 through 3.16.0 and is resolved in version 3.17.0.

Affected products

  • Apache APISIX 2.14.1 through 3.16.0

Timeline

  • 2026-06-19: advisory: NVD and Apache mailing list publication
  • 2026-06-19: disclosed
  • 2026-06-19: patched: Version 3.17.0 released

References

Related threats