Vulnerability record · CVE-2022-24112 · published 11 February 2022
CVE-2022-24112: Apache APISIX batch-requests plugin auth bypass enables RCE
Apache · Apisix
The batch-requests plugin in Apache APISIX can be abused to bypass the Admin API IP restriction because a code bug defeats the check that overrides the client IP with the real remote IP. With the default configuration and default API key, this leads to remote code execution; even when the admin key or Admin API port is changed, the IP restriction bypass against the data panel remains possible.
Description
An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulnerable to remote code execution. When the admin key was changed or the port of Admin API was changed to a port different from the data panel, the impact is lower. But there is still a risk to bypass the IP restriction of Apache APISIX's data panel. There is a check in the batch-requests plugin which overrides the client IP with its real remote IP. But due to a bug in the code, this check can be bypassed.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, KEV-listed exploitation, and EPSS above 0.96 make this an urgent patch-first issue.
What it is
The batch-requests plugin in Apache APISIX can be abused to bypass the Admin API IP restriction because a code bug defeats the check that overrides the client IP with the real remote IP. With the default configuration and default API key, this leads to remote code execution; even when the admin key or Admin API port is changed, the IP restriction bypass against the data panel remains possible.
Impact
An unauthenticated attacker can reach the Admin API and, under default configuration, execute arbitrary code on the APISIX host. Where defaults were changed, the attacker can still bypass the data panel IP restriction.
Attack surface
Reachable over the network through the batch-requests plugin; the CVSS vector shows no privileges and no user interaction required. The flaw is an authentication bypass by spoofing (CWE-290) of the client IP check.
Exploitation
CISA KEV lists it as exploited with a 2022-09-15 remediation due date, and EPSS is 0.96001 (99.873rd percentile). Multiple references are tagged Exploit, indicating public exploit material exists.
What to do
- Apply the Apache APISIX update per vendor instructions (patch first).
- Change the default Admin API key and move the Admin API to a port separate from the data panel.
- Restrict network access to the Admin API and batch-requests plugin to trusted management networks.
- Disable the batch-requests plugin if it is not required.
- Monitor vendor and CISA guidance for any additional hardening steps.
Detection
- Alert on requests to the batch-requests plugin that target Admin API paths.
- Monitor Admin API access from unexpected source IPs or external networks.
- Look for signs of code execution or unexpected process creation on APISIX hosts.
- Review logs for attempts to spoof or override client IP in batch-requests calls.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-24112 to the Known Exploited Vulnerabilities catalog on 25 August 2022 as "Apache APISIX Authentication Bypass Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 September 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-24112 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-24112), CISA KEV, FIRST EPSS (scores of 2026-09-22). This page is refreshed as NVD updates the record.