Junglewise Threat Intelligence

CVE-2026-49872: Apache APISIX improper authentication in cas-auth plugin

CVE-2026-49872 · Severity: info · CVSS 5.3 · Published 2026-06-19

Technologies: Apache APISIX. Vendors: Apache.

Executive brief

Apache APISIX is a cloud-native API gateway used to manage and secure web traffic. A security flaw in its Central Authentication Service (CAS) plugin allows an attacker to potentially bypass intended security checks by using credentials from an unauthorized source. This could allow unauthorized users to gain access to protected internal services and data.

Technical details

An improper authentication vulnerability (CWE-287) exists in the Apache APISIX cas-auth plugin. When the plugin is enabled on a route, the system fails to properly validate the source of authentication credentials, potentially allowing an attacker to provide valid credentials from a different, unintended source to gain access. The vulnerability is reachable over the network and requires the cas-auth plugin to be active. The issue is resolved in version 3.17.0.

Affected products

  • Apache APISIX 3.0.0 through 3.16.0

Timeline

  • 2026-06-19: disclosed
  • 2026-06-19: advisory
  • 2026-06-19: patched: Fixed in version 3.17.0

References

Related threats