Improper validation of integrity check value in Apache APISIX - CVE-2026-49230
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication.
The vulnerability exists due to improper validation of integrity check value in the jwe-decrypt plugin when processing JWE tokens under the default configuration. A remote attacker can supply a crafted JWE token to bypass authentication.
Only the jwe-decrypt plugin under the default configuration is vulnerable.