PT-2026-50884 · Apache · Apache Apisix

·

CVE-2026-44087

·

Published

2026-06-19

·

Updated

2026-06-23

CVSS v2.0

9.4

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Apache APISIX versions 2.3 through 3.16.0
Description The openid-connect plugin under default configuration contains an issue where insufficient verification of data authenticity allows an attacker to spoof identity headers. This can lead to unauthorized access to protected resources.
Recommendations Upgrade to version 3.17.0.

Exploit

Fix

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-08936
BIT-APISIX-2026-44087
CVE-2026-44087

Affected Products

Apache Apisix