Description
Improper Authentication vulnerability in Apache APISIX.

On a route using openid-connect plugin with remote introspection against an authorization server that serves multiple issuers, a token that introspects as active for one issuer may get accepted on a route restricted to another. This issue affects Apache APISIX: from 3.12.0 through 3.18.0.

Users are recommended to upgrade to version 3.19.0, which fixes the issue.
Published: 2026-10-01
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: Authentication Bypass
Action: Apply Patch
AI Analysis

Impact

This vulnerability is an improper authentication flaw that allows a token authenticated for one issuer to be accepted on a route that is intended for another issuer. An attacker can issue a valid token from a trusted issuer and then use it to access resources protected by a different issuer, effectively bypassing intended access controls. The weakness is classified as CWE-287.

Affected Systems

Apache APISIX versions 3.12.0 through 3.18.0 that use the openid-connect plugin with remote introspection against an authorization server serving multiple issuers are affected. The issue occurs on routes configured with this plugin and defaults to accepting any introspected token marked active regardless of issuer mismatch.

Risk and Exploitability

With a CVSS score of 5.1 the vulnerability presents moderate risk, and it is not listed in CISA KEV. The EPSS score is unavailable, but the attack path is remote: an adversary can send HTTP requests containing a token for one issuer to a gateway route intended for another issuer. If the gateway accepts the token, the attacker can gain unauthorized access to protected services. No additional exploitation conditions are specified, suggesting the flaw can be exercised from a standard client or attacker role.

Generated by OpenCVE AI on October 1, 2026 at 13:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache APISIX to version 3.19.0 or later, which eliminates the issuer validation flaw.
  • Verify that each route using the openid-connect plugin enforces issuer validation and that introspection responses match the configured issuer.
  • If an upgrade cannot occur immediately, restrict openid-connect usage to routes with a single, explicitly configured issuer and reject tokens from any other issuer before they are processed.

Generated by OpenCVE AI on October 1, 2026 at 13:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache apisix
Vendors & Products Apache
Apache apisix

Thu, 01 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
References

Thu, 01 Oct 2026 11:30:00 +0000

Type Values Removed Values Added
Description Improper Authentication vulnerability in Apache APISIX. On a route using openid-connect plugin with remote introspection against an authorization server that serves multiple issuers, a token that introspects as active for one issuer may get accepted on a route restricted to another. This issue affects Apache APISIX: from 3.12.0 through 3.18.0. Users are recommended to upgrade to version 3.19.0, which fixes the issue.
Title Apache APISIX: Openid-connect introspection validation issue
Weaknesses CWE-287
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-01T14:44:30.267Z

Reserved: 2026-09-21T09:22:14.849Z

Link: CVE-2026-94276

cve-icon Vulnrichment

Updated: 2026-10-01T13:11:03.471Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T12:17:17.347

Modified: 2026-10-01T15:17:36.580

Link: CVE-2026-94276

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T15:35:33Z

Weaknesses