https://seclists.org/oss-sec/2026/q2/982: CVE-2026-49871: Apache APISIX: cas-auth login CSRF / session injection issue
Published Jun 19, 2026
·Updated
Affected Software
1 affected component
Apache APISIX>=3.0.0<=3.16.0
Frequently Asked Questions
1
What is the severity of CVE-2026-49871?
CVE-2026-49871 is classified as a cross-site request forgery (CSRF) vulnerability which poses a significant risk to affected users.
2
How do I fix CVE-2026-49871?
To mitigate CVE-2026-49871, update Apache APISIX to version 3.17.0 or later where this vulnerability has been addressed.
3
Which versions are affected by CVE-2026-49871?
CVE-2026-49871 affects Apache APISIX versions 3.0.0 through 3.16.0.
4
What is the impact of CVE-2026-49871 on Apache APISIX?
The impact of CVE-2026-49871 allows attackers to perform unauthorized actions on behalf of authenticated users, potentially leading to session hijacking.
5
Is CVE-2026-49871 a remote exploitation vulnerability?
Yes, CVE-2026-49871 can be exploited remotely if the victim is tricked into visiting a malicious webpage.