CVE-2026-44046: Apache APISIX: wolf-rbac plugin Identity Spoofing
Use of Less Trusted Source vulnerability in Apache APISIX.
Attacker can take advantage of wolf-rbac plugin under default configuration to potentially pollute logs with spoofed identity information and exploit IP based access control rules. This issue affects Apache APISIX: from 1.2.0 through 3.16.0.
Users are recommended to upgrade to version 3.17.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache APISIX (wolf-rbac plugin)to a version that resolves this vulnerability.Fixed in 3.17.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44046?
CVE-2026-44046 has a severity rating of low, with a CVSS score of 4.0.
How do I fix CVE-2026-44046?
To mitigate CVE-2026-44046, ensure that the wolf-rbac plugin is configured securely and validate identity information appropriately.
What does CVE-2026-44046 affect?
CVE-2026-44046 affects Apache APISIX versions from 1.2.0 through 3.16.0.
What type of vulnerability is CVE-2026-44046?
CVE-2026-44046 is classified as a use of less trusted source vulnerability.
What can an attacker do with CVE-2026-44046?
An attacker can potentially spoof identity information and exploit IP-based access control rules due to CVE-2026-44046.