Cross-site request forgery in Apache APISIX - CVE-2026-49871
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause actions taken by the victim upstream to be attributed to the attacker's identity.
The vulnerability exists due to cross-site request forgery in the cas-auth plugin when handling login requests under default configurations. A remote attacker can send the victim to a webpage controlled by them to cause actions taken by the victim upstream to be attributed to the attacker's identity.
The victim's browser can become authenticated as a different identity.