CVE-2026-49230
Received Received - Intake
Authentication Bypass in Apache APISIX jwe-decrypt Plugin

Publication date: 2026-06-19

Last updated on: 2026-06-19

Assigner: Apache Software Foundation

Description
Improper Validation of Integrity Check Value vulnerability in Apache APISIX. The jwe-decrypt plugin under default configuration is vulnerable to authentication bypass.Β  This issue affects Apache APISIX: from 3.8.0 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-19
Last Modified
2026-06-19
Generated
2026-06-19
AI Q&A
2026-06-19
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
apache apisix From 3.8.0 (inc) to 3.16.0 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-354 The product does not validate or incorrectly validates the integrity check values or "checksums" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

CVE-2026-49230 is an authentication bypass vulnerability in Apache APISIX affecting versions 3.8.0 through 3.16.0. It arises from improper validation of the Integrity Check Value in the jwe-decrypt plugin when used under its default configuration.

This flaw allows attackers to bypass authentication mechanisms, potentially gaining unauthorized access.

Users are recommended to upgrade to version 3.17.0 or later to fix this issue.

Impact Analysis

This vulnerability can allow attackers to bypass authentication controls in Apache APISIX, potentially granting unauthorized access to protected resources or services.

Such unauthorized access could lead to data exposure, manipulation, or other security breaches depending on the deployment context.

Mitigation Strategies

To mitigate the authentication bypass vulnerability in Apache APISIX caused by improper validation of the Integrity Check Value in the jwe-decrypt plugin, users are recommended to upgrade Apache APISIX to version 3.17.0 or later.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-49230. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart