CVE-2026-49230: Apache APISIX: Authentication bypass in jwe-decrypt
Improper Validation of Integrity Check Value vulnerability in Apache APISIX.
The jwe-decrypt plugin under default configuration is vulnerable to authentication bypass. This issue affects Apache APISIX: from 3.8.0 through 3.16.0.
Users are recommended to upgrade to version 3.17.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache APISIXto a version that resolves this vulnerability.Fixed in 3.17.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-49230?
The severity of CVE-2026-49230 is medium, with a score of 6.3 on the CVSS scale.
How do I fix CVE-2026-49230?
To fix CVE-2026-49230, upgrade Apache APISIX to version 3.17.0 or later.
What types of systems are affected by CVE-2026-49230?
CVE-2026-49230 affects all versions of Apache APISIX from 3.8.0 through 3.16.0.
What kind of vulnerability is CVE-2026-49230?
CVE-2026-49230 is an Improper Validation of Integrity Check Value vulnerability.
What could an attacker exploit in CVE-2026-49230?
An attacker could exploit CVE-2026-49230 to bypass authentication due to a flaw in the jwe-decrypt plugin.