Boletines de Vulnerabilidades

CVE-2026-47339

   
Software afectado APACHE
 
Incorrect Authorization vulnerability in Apache APISIX.

An attacker can capitalise on authz-casdoor plugin under default configuration to authenticate themselves with credentials from a different source.
This issue affects Apache APISIX: from 2.14.1 through 3.16.0.

Users are recommended to upgrade to version 3.17.0, which fixes the issue.

Link:

https://nvd.nist.gov/vuln/detail/CVE-2026-47339