Executive brief
Apache APISIX is a cloud-native API gateway used to manage and secure web traffic. A security flaw in its Central Authentication Service (CAS) plugin allows an attacker to potentially bypass intended security checks by using credentials from an unauthorized source. This could allow unauthorized users to gain access to protected internal services and data.
Technical details
An improper authentication vulnerability (CWE-287) exists in the Apache APISIX cas-auth plugin. When the plugin is enabled on a route, the system fails to properly validate the source of authentication credentials, potentially allowing an attacker to provide valid credentials from a different, unintended source to gain access. The vulnerability is reachable over the network and requires the cas-auth plugin to be active. The issue is resolved in version 3.17.0.
Affected products
- Apache APISIX 3.0.0 through 3.16.0
Timeline
- 2026-06-19: disclosed
- 2026-06-19: advisory
- 2026-06-19: patched: Fixed in version 3.17.0