Apache APISIX 3.8.0-3.16.0 Auth Bypass via JWE Decrypt
CVE-2026-49230 Published on June 19, 2026

Apache APISIX: Authentication bypass in jwe-decrypt
Improper Validation of Integrity Check Value vulnerability in Apache APISIX. The jwe-decrypt plugin under default configuration is vulnerable to authentication bypass.  This issue affects Apache APISIX: from 3.8.0 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue.

Vendor Advisory NVD

Weakness Type

Improper Validation of Integrity Check Value

The software does not validate or incorrectly validates the integrity check values or "checksums" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission. Improper validation of checksums before use results in an unnecessary risk that can easily be mitigated. The protocol specification describes the algorithm used for calculating the checksum. It is then a simple matter of implementing the calculation and verifying that the calculated checksum and the received checksum match. Improper verification of the calculated checksum and the received checksum can lead to far greater consequences.


Products Associated with CVE-2026-49230

Want to know whenever a new CVE is published for Apache Apisix? stack.watch will email you.

 

Affected Versions

Apache Software Foundation Apache APISIX: