Skip to content
CVSS 9.1 · CRITICAL

CVE-2026-39999

Authentication Bypass by Spoofing vulnerability in Apache APISIX. The attacker can completely bypass authentication capitalising on certain configurations of jwt-auth plugin. This issue affects Apache APISIX: from v2.2 through v3.16.0. Users are recommended to upgrade to version v3.17.0, which fixes the issue.

View on NVD

Analysis

Apache APISIX versions 2.2 to 3.16.0 contain a critical vulnerability in the jwt-auth plugin that allows attackers to completely bypass authentication. This allows unauthorized access to all services behind the gateway. Users are urged to upgrade to version 3.17.0 immediately.

Relevant roles

BackendCyberSecurityCloudKubernetesDockerLinux

Severity

Score: 9.1(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: UNCHANGED
C: HIGH
I: HIGH
A: NONE
Weakness (CWE): CWE-290

EPSS

Probability of exploitation (next 30 days): 0.0041 (0.4%)
Percentile: 32.6%
EPSS: 2026-06-23

Affects

apache:apisix

Technical description

Authentication Bypass by Spoofing vulnerability in Apache APISIX. The attacker can completely bypass authentication capitalising on certain configurations of jwt-auth plugin. This issue affects Apache APISIX: from v2.2 through v3.16.0. Users are recommended to upgrade to version v3.17.0, which fixes the issue.

Published: 6/19/2026, 2:16:21 PM
Last modified: 6/23/2026, 3:08:22 PM

References

HomeEventsBlogResourcesTeam