CVE-2026-39999
Received Received - Intake
Authentication Bypass in Apache APISIX via JWT-Auth Plugin

Publication date: 2026-06-19

Last updated on: 2026-06-19

Assigner: Apache Software Foundation

Description
Authentication Bypass by Spoofing vulnerability in Apache APISIX. The attacker can completely bypass authentication capitalising on certain configurations of jwt-auth plugin. This issue affects Apache APISIX: from v2.2 through v3.16.0. Users are recommended to upgrade to version v3.17.0, which fixes the issue.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-19
Last Modified
2026-06-19
Generated
2026-06-19
AI Q&A
2026-06-19
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 3 associated CPEs
Vendor Product Version / Range
apache apisix From 2.2 (inc) to 3.16.0 (inc)
apache apisix 3.17.0
apache apisix 3.16.1
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-290 This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Compliance Impact

The vulnerability allows attackers to completely bypass authentication in Apache APISIX under certain configurations of the jwt-auth plugin.

Such an authentication bypass can lead to unauthorized access to sensitive data or systems, which may result in non-compliance with common standards and regulations like GDPR and HIPAA that require strict access controls and protection of personal or health information.

Therefore, if exploited, this vulnerability could compromise compliance by exposing protected data or systems to unauthorized users.

Users are recommended to upgrade to version 3.17.0 (or 3.16.1 as per Resource 2) to fix the issue and mitigate compliance risks.

Executive Summary

CVE-2026-39999 is an authentication bypass vulnerability in Apache APISIX that arises due to a JWT algorithm confusion issue.

Attackers can exploit certain configurations of the jwt-auth plugin to completely bypass authentication, allowing unauthorized access.

This affects Apache APISIX versions from 2.2 through 3.16.0.

Impact Analysis

This vulnerability allows attackers to bypass authentication entirely, potentially granting them unauthorized access to protected resources or services managed by Apache APISIX.

Such unauthorized access can lead to data exposure, manipulation, or disruption of services.

Mitigation Strategies

To mitigate the authentication bypass vulnerability in Apache APISIX, users should upgrade their Apache APISIX installation to version 3.17.0 or later, where the issue is fixed.

This vulnerability affects versions from 2.2 through 3.16.0, so upgrading beyond these versions is critical to prevent exploitation.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-39999. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart