CVE-2026-39999
Critical · CVSS 9.1Apache APISIX — Authentication Bypass by Spoofing (CWE-290) via jwt-auth plugin misconfiguration
- CVSS
- 9.1
- nvd
- EPSS
- 0.41%
- 33th pct
- KEV
- No
- Class
- other
- CWE-290
Description
Authentication Bypass by Spoofing vulnerability in Apache APISIX. The attacker can completely bypass authentication capitalising on certain configurations of jwt-auth plugin. This issue affects Apache APISIX: from v2.2 through v3.16.0. Users are recommended to upgrade to version v3.17.0, which fixes the issue.
Search profile — drives PoC discovery
Symbols jwt-authjwt_authapisixauthentication bypassplugintoken spoofingJWTconsumerupstream
Keywords CVE-2026-39999Apache APISIXjwt-authauthentication bypassspoofingAPISIX JWTAPISIX auth bypassCWE-290APISIX plugin bypassAPISIX v3.16APISIX exploit
Versions: v2.2 through v3.16.0
References
Status: enriched · ingested 2026-06-23T18:00:15.000Z · profiled 2026-06-24T06:30:26.000Z