CVE-2026-94276
Deferred Deferred - Pending Action

Improper Authentication in Apache APISIX OpenID-Connect Plugin

Vulnerability report for CVE-2026-94276, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: Apache Software Foundation

Description

Improper Authentication vulnerability in Apache APISIX. On a route using openid-connect plugin with remote introspection against an authorization server that serves multiple issuers, a token that introspects as active for one issuer may getΒ accepted on a route restricted to another.Β This issue affects Apache APISIX: from 3.12.0 through 3.18.0. Users are recommended to upgrade to version 3.19.0, which fixes the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
apache apisix From 3.12.0 (inc) to 3.18.0 (inc)
apache apisix 3.19.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Improper Authentication issue in Apache APISIX. It occurs when using the openid-connect plugin with remote introspection against an authorization server that supports multiple issuers. A token valid for one issuer may be incorrectly accepted on a route restricted to a different issuer.

Impact Analysis

This vulnerability could allow unauthorized access to restricted routes if an attacker presents a token valid for one issuer on a route meant for another. This could lead to data exposure or unauthorized actions depending on the route's purpose.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized access to restricted routes due to improper authentication. If tokens are incorrectly accepted across different issuers, it may lead to unauthorized data exposure or processing, violating confidentiality and access control requirements in these regulations.

Mitigation Strategies

Upgrade Apache APISIX to version 3.19.0 or later to fix the improper authentication issue in the openid-connect plugin.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-94276. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart