← Vulnerability feed

Vulnerability record · CVE-2022-24112 · published 11 February 2022

CVE-2022-24112: Apache APISIX batch-requests plugin auth bypass enables RCE

Apache · Apisix

The batch-requests plugin in Apache APISIX can be abused to bypass the Admin API IP restriction because a code bug defeats the check that overrides the client IP with the real remote IP. With the default configuration and default API key, this leads to remote code execution; even when the admin key or Admin API port is changed, the IP restriction bypass against the data panel remains possible.

9.8 CVSS 3.1 Critical CISA KEV since 25 Aug 2022 EPSS 96% · top 0.1% CWE-290 · Authentication bypass by spoofing
9.8CVSS 3.1 base score, v2 7.5
96%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
9References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulnerable to remote code execution. When the admin key was changed or the port of Admin API was changed to a port different from the data panel, the impact is lower. But there is still a risk to bypass the IP restriction of Apache APISIX's data panel. There is a check in the batch-requests plugin which overrides the client IP with its real remote IP. But due to a bug in the code, this check can be bypassed.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 9.8, KEV-listed exploitation, and EPSS above 0.96 make this an urgent patch-first issue.

What it is

The batch-requests plugin in Apache APISIX can be abused to bypass the Admin API IP restriction because a code bug defeats the check that overrides the client IP with the real remote IP. With the default configuration and default API key, this leads to remote code execution; even when the admin key or Admin API port is changed, the IP restriction bypass against the data panel remains possible.

Impact

An unauthenticated attacker can reach the Admin API and, under default configuration, execute arbitrary code on the APISIX host. Where defaults were changed, the attacker can still bypass the data panel IP restriction.

Attack surface

Reachable over the network through the batch-requests plugin; the CVSS vector shows no privileges and no user interaction required. The flaw is an authentication bypass by spoofing (CWE-290) of the client IP check.

Exploitation

CISA KEV lists it as exploited with a 2022-09-15 remediation due date, and EPSS is 0.96001 (99.873rd percentile). Multiple references are tagged Exploit, indicating public exploit material exists.

What to do

  • Apply the Apache APISIX update per vendor instructions (patch first).
  • Change the default Admin API key and move the Admin API to a port separate from the data panel.
  • Restrict network access to the Admin API and batch-requests plugin to trusted management networks.
  • Disable the batch-requests plugin if it is not required.
  • Monitor vendor and CISA guidance for any additional hardening steps.

Detection

  • Alert on requests to the batch-requests plugin that target Admin API paths.
  • Monitor Admin API access from unexpected source IPs or external networks.
  • Look for signs of code execution or unexpected process creation on APISIX hosts.
  • Review logs for attempts to spoof or override client IP in batch-requests calls.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2022-24112 to the Known Exploited Vulnerabilities catalog on 25 August 2022 as "Apache APISIX Authentication Bypass Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 September 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-24112 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed9.8CVE-2022-25757Apache apisix improper input validation vulnerabilityIn Apache APISIX before 2.13.0, when decoding JSON with duplicate keys, lua-cjson will choose the last occurred value as the result. By passing a JSO…EPSS 2.5%9.1CVE-2026-31908Apache apisix vulnerabilityHeader injection vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-auth plugin to inject malicious …EPSS 0.60%8.7CVE-2026-75005Apache apisix vulnerabilityInefficient Algorithmic Complexity vulnerability in Apache APISIX. A single small request can pin a gateway worker at 100% CPU for an extended period…EPSS 0.74%7.8CVE-2025-27446Apache apisix incorrect permission assignment vulnerabilityIncorrect Permission Assignment for Critical Resource vulnerability in Apache APISIX(java-plugin-runner). Local listening file permissions in APISIX …EPSS 0.19%7.5CVE-2026-31923Apache apisix cleartext transmission vulnerabilityCleartext Transmission of Sensitive Information vulnerability in Apache APISIX. This can occur due to `ssl_verify` in openid-connect plugin configura…EPSS 0.37%7.5CVE-2025-62232Apache apisix sensitive information in log file vulnerabilitySensitive data exposure via logging in basic-auth leads to plaintext usernames and passwords written to error logs and forwarded to log sinks when lo…EPSS 0.44%7.5CVE-2022-29266Apache apisix error message information leak vulnerabilityIn APache APISIX before 3.13.1, the jwt-auth plugin has a security issue that leaks the user's secret key because the error message returned from the…EPSS 8.1%

Source: NIST National Vulnerability Database (record CVE-2022-24112), CISA KEV, FIRST EPSS (scores of 2026-09-22). This page is refreshed as NVD updates the record.