Improper Authentication in Apache APISIX - CVE-2026-94276
Published: October 1, 2026
Vulnerability details
The vulnerability allows a remote user to gain unauthorized access to resources restricted to another issuer.
The vulnerability exists due to improper authentication in the openid-connect plugin when performing remote token introspection. A remote user can present a token active for one issuer to a route restricted to another issuer to gain unauthorized access to resources restricted to another issuer.
The authorization server must serve multiple issuers.