Junglewise Threat Intelligence

CVE-2026-49230: Apache APISIX authentication bypass in jwe-decrypt plugin

CVE-2026-49230 · Severity: info · CVSS 6.3 · Published 2026-06-19

Technologies: Apache APISIX. Vendors: Apache.

Executive brief

Apache APISIX, a popular cloud-native API gateway used to manage and secure web traffic, contains a security flaw in its JWE decryption plugin. Under default settings, an attacker can bypass authentication mechanisms intended to protect backend services. This could allow unauthorized access to sensitive internal applications or data.

Technical details

An Improper Validation of Integrity Check Value (CWE-354) vulnerability exists in the Apache APISIX jwe-decrypt plugin. When running under default configurations, the plugin fails to correctly verify the integrity of JSON Web Encryption (JWE) tokens. A remote, unauthenticated attacker can exploit this flaw to bypass authentication requirements and gain unauthorized access to protected resources. The issue affects versions 3.8.0 through 3.16.0 and is resolved in version 3.17.0.

Affected products

  • Apache APISIX 3.8.0 through 3.16.0

Timeline

  • 2026-06-19: advisory: NVD and Apache mailing list publication
  • 2026-06-19: patched: Version 3.17.0 released to address the issue

References

Related threats