Authentication Bypass by Spoofing in Apache APISIX - CVE-2026-49231
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to assume higher privileges on the upstream service.
The vulnerability exists due to improper access control in opa plugin when relaying spoofed identity headers to upstream services. A remote attacker can send spoofed identity headers to assume higher privileges on the upstream service.
Exploitation requires non-default configuration in the plugin.