CVE-2026-49231: Apache APISIX: Identity spoofing issue in APISIX opa plugin
Authentication Bypass by Spoofing vulnerability in opa plugin.
An attacker could relay spoofed identity headers to upstream capitalising on non-default configuration in opa plugin.
This could allow the attacker to assume higher privileges on the upstream service. This issue affects Apache APISIX: from 3.5.0 through 3.16.0.
Users are recommended to upgrade to version 3.17.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache APISIXto a version that resolves this vulnerability.Fixed in 3.17.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-49231?
The severity of CVE-2026-49231 is rated as low with a CVSS score of 4.0.
What is CVE-2026-49231 about?
CVE-2026-49231 is an identity spoofing vulnerability in the Apache APISIX opa plugin that allows an attacker to bypass authentication.
How do I fix CVE-2026-49231?
To fix CVE-2026-49231, ensure that the OPA plugin is configured with default settings to prevent spoofing of identity headers.
Who is affected by CVE-2026-49231?
CVE-2026-49231 affects users of Apache APISIX who are using the OPA plugin with non-default configurations.
What can an attacker do with CVE-2026-49231?
An attacker exploiting CVE-2026-49231 could relay spoofed identity headers to gain higher privileges on the upstream service.