CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-49871

Critical · CVSS 9.3

Apache APISIX — Cross-Site Request Forgery (CSRF) authentication identity swap

CVSS
9.3
nvd
EPSS
0.23%
13th pct
KEV
No
Class
other
CWE-352

Description

Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin under default configurations. This defect allows a remote attacker that manages to send a victim to a webpage controlled by them can cause the victim's browser to become authenticated as a different identity. Actions the victim takes upstream are then attributed to attackers identity. This issue affects Apache APISIX: from 3.0.0 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue.

Search profile — drives PoC discovery

Symbols cas-authcas_authapisix/plugins/cas-authCAScas_callbackcsrf_tokenanti_csrfsessionidentity
Keywords CVE-2026-49871Apache APISIXcas-authCSRFpluginauthenticationidentity swapapisix csrfapisix cas plugin poc
Versions: 3.0.0 through 3.16.0

References

Status: enriched · ingested 2026-06-23T18:00:15.000Z · profiled 2026-06-24T06:30:26.000Z