CVE-2026-49871: Apache APISIX: cas-auth login CSRF / session injection issue
Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin under default configurations.
This defect allows a remote attacker that manages to send a victim to a webpage controlled by them can cause the victim's browser to become authenticated as a different identity.
Actions the victim takes upstream are then attributed to attackers identity.
This issue affects Apache APISIX: from 3.0.0 through 3.16.0.
Users are recommended to upgrade to version 3.17.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache APISIXto a version that resolves this vulnerability.Fixed in 3.17.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-49871?
CVE-2026-49871 has a low severity rating of 2.1.
How do I fix CVE-2026-49871?
To fix CVE-2026-49871, ensure that the cas-auth plugin is configured with appropriate CSRF protection mechanisms.
What type of vulnerability is CVE-2026-49871?
CVE-2026-49871 is a Cross-Site Request Forgery (CSRF) vulnerability.
What can an attacker achieve using CVE-2026-49871?
An attacker can cause a victim's browser to authenticate as a different identity by directing them to a malicious webpage.
Which software is affected by CVE-2026-49871?
CVE-2026-49871 affects the Apache APISIX software, specifically the cas-auth plugin.