CVE-2026-49872: Apache APISIX: Improper authentication in cas-auth plugin
Improper Authentication vulnerability in Apache APISIX.
When the cas-auth plugin is used in a route, an attacker can possibly authenticate itself with credentials from a different source. This issue affects Apache APISIX: from 3.0.0 through 3.16.0.
Users are recommended to upgrade to version 3.17.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache APISIXto a version that resolves this vulnerability.Fixed in 3.17.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-49872?
CVE-2026-49872 has a medium severity rating of 5.3 on the CVSS scale.
How do I fix CVE-2026-49872?
To fix CVE-2026-49872, users should upgrade Apache APISIX to version 3.17.0 or later.
What systems are affected by CVE-2026-49872?
CVE-2026-49872 affects Apache APISIX versions from 3.0.0 through 3.16.0.
What type of vulnerability is CVE-2026-49872?
CVE-2026-49872 is an improper authentication vulnerability in the cas-auth plugin of Apache APISIX.
What could exploit CVE-2026-49872?
An attacker could exploit CVE-2026-49872 to authenticate with credentials from a different source when using the cas-auth plugin.