https://seclists.org/oss-sec/2026/q2/980: CVE-2026-49230: Apache APISIX: Authentication bypass in jwe-decrypt
Published Jun 19, 2026
·Updated
Affected Software
1 affected component
Apache APISIX>=3.8.0<=3.16.0
Frequently Asked Questions
1
What is the severity of CVE-2026-49230?
CVE-2026-49230 is classified as a significant security vulnerability due to its potential for authentication bypass.
2
How do I fix CVE-2026-49230?
To fix CVE-2026-49230, upgrade Apache APISIX to version 3.16.1 or later where the vulnerability has been addressed.
3
Which versions of Apache APISIX are affected by CVE-2026-49230?
CVE-2026-49230 affects Apache APISIX versions from 3.8.0 through 3.16.0.
4
What kind of vulnerability is CVE-2026-49230?
CVE-2026-49230 is an authentication bypass vulnerability caused by improper validation of integrity check values in the jwe-decrypt plugin.
5
What plugin in Apache APISIX is impacted by CVE-2026-49230?
The jwe-decrypt plugin in Apache APISIX is impacted by the CVE-2026-49230 authentication bypass vulnerability.