PT-2026-50896 · Apache Apisix+1 · Opa Plugin+1
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Apache APISIX versions 3.5.0 through 3.16.0
Description
An authentication bypass issue exists in the opa plugin. An attacker can relay spoofed identity headers to upstream services by exploiting non-default configurations in the opa plugin, potentially allowing the attacker to assume higher privileges on the upstream service.
Recommendations
Upgrade to version 3.17.0.
Exploit
Fix
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Apisix
Opa Plugin