MEDIUM 5.1 NVD
CVE-2026-94276
Improper Authentication vulnerability in Apache APISIX. On a route using openid-connect plugin with remote introspection against an authorization server that s
Improper Authentication vulnerability in Apache APISIX.
On a route using openid-connect plugin with remote introspection against an authorization server that serves multiple issuers, a token that introspects as active for one issuer may get accepted on a route restricted to another. This issue affects Apache APISIX: from 3.12.0 through 3.18.0.
Users are recommended to upgrade to version 3.19.0, which fixes the issue.
References
- https://lists.apache.org/thread.html/txn3br25kl657fh15rwcy1oht1xbpyyk
- http://www.openwall.com/lists/oss-security/2026/10/01/8
- https://www.openwall.com/lists/oss-security/2026/10/01/8
This medium severity vulnerability with a CVSS score of 5.1 was published on 2026-10-01 via NVD.
vulnfeed aggregates 12641 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.