CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-39999

Critical · CVSS 9.1

Apache APISIX — Authentication Bypass by Spoofing (CWE-290) via jwt-auth plugin misconfiguration

CVSS
9.1
nvd
EPSS
0.41%
33th pct
KEV
No
Class
other
CWE-290

Description

Authentication Bypass by Spoofing vulnerability in Apache APISIX. The attacker can completely bypass authentication capitalising on certain configurations of jwt-auth plugin. This issue affects Apache APISIX: from v2.2 through v3.16.0. Users are recommended to upgrade to version v3.17.0, which fixes the issue.

Search profile — drives PoC discovery

Symbols jwt-authjwt_authapisixauthentication bypassplugintoken spoofingJWTconsumerupstream
Keywords CVE-2026-39999Apache APISIXjwt-authauthentication bypassspoofingAPISIX JWTAPISIX auth bypassCWE-290APISIX plugin bypassAPISIX v3.16APISIX exploit
Versions: v2.2 through v3.16.0

References

Status: enriched · ingested 2026-06-23T18:00:15.000Z · profiled 2026-06-24T06:30:26.000Z