CVE-2026-39999: Apache APISIX: JWT Algorithm Confusion allows authentication bypass
Authentication Bypass by Spoofing vulnerability in Apache APISIX.
The attacker can completely bypass authentication capitalising on certain configurations of jwt-auth plugin. This issue affects Apache APISIX: from v2.2 through v3.16.0.
Users are recommended to upgrade to version v3.17.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache APISIXto a version that resolves this vulnerability.Fixed in v3.17.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-39999?
CVE-2026-39999 has a severity rating of high with a score of 7.
How do I fix CVE-2026-39999?
To fix CVE-2026-39999, upgrade Apache APISIX to version v3.17.0 or later.
What does CVE-2026-39999 affect?
CVE-2026-39999 affects Apache APISIX versions from v2.2 through v3.16.0.
What type of vulnerability is CVE-2026-39999?
CVE-2026-39999 is an authentication bypass vulnerability that allows attackers to spoof authentication.
What is the impact of CVE-2026-39999?
The impact of CVE-2026-39999 is that attackers can completely bypass authentication due to misconfigurations of the jwt-auth plugin.