PT-2026-50886 · Apache Apisix+1 · Authz-Casdoor+1

·

CVE-2026-47339

·

Published

2026-06-19

·

Updated

2026-06-23

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Apache APISIX versions 2.14.1 through 3.16.0
Description An incorrect authorization issue exists in the authz-casdoor plugin when using the default configuration. This allows an attacker to authenticate using credentials from a different source.
Recommendations Upgrade to version 3.17.0.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-08918
BIT-APISIX-2026-47339
CVE-2026-47339

Affected Products

Apache Apisix
Authz-Casdoor