Incorrect authorization in Apache APISIX - CVE-2026-47339
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to authenticate themselves with credentials from a different source.
The vulnerability exists due to improper authorization in the authz-casdoor plugin when operating under the default configuration. A remote attacker can exploit the plugin behavior to authenticate themselves with credentials from a different source.
Only deployments using the authz-casdoor plugin under the default configuration are vulnerable.