https://seclists.org/oss-sec/2026/q2/974: CVE-2026-44046: Apache APISIX: wolf-rbac plugin Identity Spoofing
Published Jun 19, 2026
·Updated
Affected Software
1 affected component
Apache APISIX>=1.2.0<=3.16.0
Frequently Asked Questions
1
What is the severity of CVE-2026-44046?
CVE-2026-44046 has been classified with a severity that allows attackers to exploit the wolf-rbac plugin in Apache APISIX.
2
How do I fix CVE-2026-44046?
To mitigate CVE-2026-44046, you should upgrade to Apache APISIX version 3.17.0 or later.
3
What versions of Apache APISIX are affected by CVE-2026-44046?
Apache APISIX versions from 1.2.0 through 3.16.0 are affected by CVE-2026-44046.
4
What type of vulnerability is CVE-2026-44046?
CVE-2026-44046 is categorized as a Use of Less Trusted Source vulnerability.
5
What is the impact of CVE-2026-44046 on Apache APISIX?
CVE-2026-44046 allows attackers to potentially pollute logs with spoofed identity information, which can lead to further exploitation.