CVE-2026-94269
Deferred
Deferred - Pending Action
Authorization Bypass via Non-Canonical Path in Apache APISIX
Vulnerability report for CVE-2026-94269, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-01
Last updated on: 2026-10-01
Assigner: Apache Software Foundation
Description
Description
Use of Non-Canonical URL paths for authorization decisions vulnerability in Apache APISIX.
In some configurations where a permissive route overlaps a protected one, a crafted encoded path can reach an upstream endpoint that the matched route's policies were never meant to cover. AΒ request that should have been rejected is served instead, giving unauthenticated access to a protected upstream endpoint. This issue affects Apache APISIX: from 2.14.1 through 3.18.0.
Users are recommended to upgrade to version 3.19.0, which fixes the issue.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| apache | apisix | From 2.14.1 (inc) to 3.18.0 (inc) |
| apache | apisix | 3.19.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-647 | The product defines policy namespaces and makes authorization decisions based on the assumption that a URL is canonical. This can allow a non-canonical URL to bypass the authorization. |