Junglewise Threat Intelligence

CVE-2026-49871: Apache APISIX CSRF in cas-auth plugin

CVE-2026-49871 · Severity: info · CVSS 2.1 · Published 2026-06-19

Technologies: Apache APISIX. Vendors: Apache.

Executive brief

Apache APISIX is a cloud-native API gateway used to manage and secure web traffic. A security flaw in its CAS authentication plugin allows an attacker to trick a user's browser into logging into a different account without their knowledge. This could lead to a user's subsequent actions being incorrectly attributed to the attacker's identity, potentially causing data confusion or operational errors.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the cas-auth plugin of Apache APISIX when using default configurations. By inducing a victim to visit a malicious webpage, a remote attacker can trigger a login request that authenticates the victim's session as an identity controlled by the attacker. This results in session injection where upstream actions performed by the victim are attributed to the attacker's credentials. The issue affects versions 3.0.0 through 3.16.0 and is resolved in version 3.17.0.

Affected products

  • Apache APISIX 3.0.0 through 3.16.0

Timeline

  • 2026-06-19: disclosed
  • 2026-06-19: advisory
  • 2026-06-19: patched: Fixed in version 3.17.0

References

Related threats