https://seclists.org/oss-sec/2026/q2/981: CVE-2026-49231: Apache APISIX: Identity spoofing issue in APISIX opa plugin
Published Jun 19, 2026
·Updated
Affected Software
1 affected component
Apache APISIX>=3.5.0<=3.16.0
Frequently Asked Questions
1
What is the severity of CVE-2026-49231?
CVE-2026-49231 has a high severity due to its potential for authentication bypass.
2
How do I fix CVE-2026-49231?
To fix CVE-2026-49231, update Apache APISIX to a patched version beyond 3.16.0.
3
What versions are affected by CVE-2026-49231?
CVE-2026-49231 affects Apache APISIX versions 3.5.0 through 3.16.0.
4
What is the nature of the vulnerability in CVE-2026-49231?
CVE-2026-49231 is an authentication bypass vulnerability allowing identity spoofing via the opa plugin.
5
Who can be impacted by CVE-2026-49231?
Users of Apache APISIX with the opa plugin configured in non-default settings are at risk from CVE-2026-49231.