CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-49230

Critical · CVSS 9.1

Apache APISIX — Improper Validation of Integrity Check Value / Authentication Bypass

CVSS
9.1
nvd
EPSS
0.23%
14th pct
KEV
No
Class
other
CWE-354

Description

Improper Validation of Integrity Check Value vulnerability in Apache APISIX. The jwe-decrypt plugin under default configuration is vulnerable to authentication bypass.  This issue affects Apache APISIX: from 3.8.0 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue.

Search profile — drives PoC discovery

Symbols jwe-decryptjwe_decryptjwe-decrypt pluginauthentication bypassintegrity checkCWE-354
Keywords CVE-2026-49230Apache APISIXjwe-decryptauthentication bypassJWE decrypt pluginAPISIX jweintegrity check bypassAPISIX 3.8.0APISIX 3.16.0
Versions: 3.8.0 through 3.16.0

References

Status: enriched · ingested 2026-06-23T18:00:15.000Z · profiled 2026-06-24T06:30:26.000Z