← Vulnerability feed

Vulnerability record · CVE-2026-49871 · published 19 June 2026

CVE-2026-49871: Apache apisix cross-site request forgery vulnerability

Apache · Apisix

Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin under default configurations. This defect allows a remote attacker that manages to send a victim to a webpage controlled by them can cause the victim's browser to become authenticated as a different identity. Actions the victim takes upstream are then attributed to attackers identity. This issue affects Apache APISIX: from 3.0.0 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue.

2.1 CVSS 4.0 Low EPSS 0.35% · top 73.9% CWE-352 · Cross-site request forgery
2.1CVSS 4.0 base score
0.35%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
23 Jun 2026Last modified by NVD

Description

Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin under default configurations. This defect allows a remote attacker that manages to send a victim to a webpage controlled by them can cause the victim's browser to become authenticated as a different identity. Actions the victim takes upstream are then attributed to attackers identity. This issue affects Apache APISIX: from 3.0.0 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue.

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-49871 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-24112Apache APISIX batch-requests plugin auth bypass enables RCEThe batch-requests plugin in Apache APISIX can be abused to bypass the Admin API IP restriction because a code bug defeats the check that overrides t…KEVEPSS 96%analysed7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed9.8CVE-2022-25757Apache apisix improper input validation vulnerabilityIn Apache APISIX before 2.13.0, when decoding JSON with duplicate keys, lua-cjson will choose the last occurred value as the result. By passing a JSO…EPSS 2.5%9.1CVE-2026-31908Apache apisix vulnerabilityHeader injection vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-auth plugin to inject malicious …EPSS 0.60%8.7CVE-2026-75005Apache apisix vulnerabilityInefficient Algorithmic Complexity vulnerability in Apache APISIX. A single small request can pin a gateway worker at 100% CPU for an extended period…EPSS 0.74%7.8CVE-2025-27446Apache apisix incorrect permission assignment vulnerabilityIncorrect Permission Assignment for Critical Resource vulnerability in Apache APISIX(java-plugin-runner). Local listening file permissions in APISIX …EPSS 0.19%7.5CVE-2026-31923Apache apisix cleartext transmission vulnerabilityCleartext Transmission of Sensitive Information vulnerability in Apache APISIX. This can occur due to `ssl_verify` in openid-connect plugin configura…EPSS 0.37%7.5CVE-2025-62232Apache apisix sensitive information in log file vulnerabilitySensitive data exposure via logging in basic-auth leads to plaintext usernames and passwords written to error logs and forwarded to log sinks when lo…EPSS 0.44%

Source: NIST National Vulnerability Database (record CVE-2026-49871), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.