Use of Less Trusted Source in Apache APISIX - CVE-2026-44046
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to spoof identity information and bypass IP-based access control rules.
The vulnerability exists due to use of a less trusted source in the wolf-rbac plugin when processing identity information under the default configuration. A remote attacker can supply spoofed identity information to spoof identity information and bypass IP-based access control rules.
The issue can also lead to log pollution with spoofed identity information.