Impact
This vulnerability is an improper authentication flaw that allows a token authenticated for one issuer to be accepted on a route that is intended for another issuer. An attacker can issue a valid token from a trusted issuer and then use it to access resources protected by a different issuer, effectively bypassing intended access controls. The weakness is classified as CWE-287.
Affected Systems
Apache APISIX versions 3.12.0 through 3.18.0 that use the openid-connect plugin with remote introspection against an authorization server serving multiple issuers are affected. The issue occurs on routes configured with this plugin and defaults to accepting any introspected token marked active regardless of issuer mismatch.
Risk and Exploitability
With a CVSS score of 5.1 the vulnerability presents moderate risk, and it is not listed in CISA KEV. The EPSS score is unavailable, but the attack path is remote: an adversary can send HTTP requests containing a token for one issuer to a gateway route intended for another issuer. If the gateway accepts the token, the attacker can gain unauthorized access to protected services. No additional exploitation conditions are specified, suggesting the flaw can be exercised from a standard client or attacker role.
OpenCVE Enrichment