CVE-2026-49230
Critical · CVSS 9.1Apache APISIX — Improper Validation of Integrity Check Value / Authentication Bypass
- CVSS
- 9.1
- nvd
- EPSS
- 0.23%
- 14th pct
- KEV
- No
- Class
- other
- CWE-354
Description
Improper Validation of Integrity Check Value vulnerability in Apache APISIX. The jwe-decrypt plugin under default configuration is vulnerable to authentication bypass. This issue affects Apache APISIX: from 3.8.0 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue.
Search profile — drives PoC discovery
Symbols jwe-decryptjwe_decryptjwe-decrypt pluginauthentication bypassintegrity checkCWE-354
Keywords CVE-2026-49230Apache APISIXjwe-decryptauthentication bypassJWE decrypt pluginAPISIX jweintegrity check bypassAPISIX 3.8.0APISIX 3.16.0
Versions: 3.8.0 through 3.16.0
References
Status: enriched · ingested 2026-06-23T18:00:15.000Z · profiled 2026-06-24T06:30:26.000Z