CVE-2026-39999
Authentication Bypass by Spoofing vulnerability in Apache APISIX. The attacker can completely bypass authentication capitalising on certain configurations of jwt-auth plugin. This issue affects Apache APISIX: from v2.2 through v3.16.0. Users are recommended to upgrade to version v3.17.0, which fixes the issue.
View on NVDAnalysis
Apache APISIX versions 2.2 to 3.16.0 contain a critical vulnerability in the jwt-auth plugin that allows attackers to completely bypass authentication. This allows unauthorized access to all services behind the gateway. Users are urged to upgrade to version 3.17.0 immediately.
Relevant roles
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NCWE-290EPSS
Affects
apache:apisixTechnical description
Authentication Bypass by Spoofing vulnerability in Apache APISIX. The attacker can completely bypass authentication capitalising on certain configurations of jwt-auth plugin. This issue affects Apache APISIX: from v2.2 through v3.16.0. Users are recommended to upgrade to version v3.17.0, which fixes the issue.