Skip to content
CVSS 9.1 · CRITICAL

CVE-2026-39999

Authentication Bypass by Spoofing vulnerability in Apache APISIX. The attacker can completely bypass authentication capitalising on certain configurations of jwt-auth plugin. This issue affects Apache APISIX: from v2.2 through v3.16.0. Users are recommended to upgrade to version v3.17.0, which fixes the issue.

Ver en NVD

Análisis

Apache APISIX versions 2.2 to 3.16.0 contain a critical vulnerability in the jwt-auth plugin that allows attackers to completely bypass authentication. This allows unauthorized access to all services behind the gateway. Users are urged to upgrade to version 3.17.0 immediately.

Roles relevantes

BackendCyberSecurityCloudKubernetesDockerLinux

Severidad

Puntaje: 9.1(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: UNCHANGED
C: HIGH
I: HIGH
A: NONE
Tipo de falla (CWE): CWE-290

EPSS

Probabilidad de explotación (próx. 30 días): 0.0041 (0.4%)
Percentil: 32.6%
EPSS: 2026-06-23

Afecta

apache:apisix

Descripción técnica

Authentication Bypass by Spoofing vulnerability in Apache APISIX. The attacker can completely bypass authentication capitalising on certain configurations of jwt-auth plugin. This issue affects Apache APISIX: from v2.2 through v3.16.0. Users are recommended to upgrade to version v3.17.0, which fixes the issue.

Publicada: 19/6/2026, 14:16:21
Última modificación: 23/6/2026, 15:08:22

Referencias

InicioEventosBlogRecursosEquipo