Improper Authentication in Apache APISIX - CVE-2026-47341
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication.
The vulnerability exists due to improper authentication in hmac-auth when validating HMAC-authenticated requests under certain configurations. A remote attacker can replay a captured token to bypass authentication.
The issue allows token reuse without expiry enforcement under affected configurations.