The attacker can completely bypass authentication capitalising on certain configurations of jwt-auth plugin.
This issue affects Apache APISIX: from v2.2 through v3.16.0.
Users are recommended to upgrade to version v3.17.0, which fixes the issue.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 22 Jun 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 19 Jun 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache apache Apisix |
|
| Vendors & Products |
Apache
Apache apache Apisix |
Fri, 19 Jun 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Authentication Bypass by Spoofing vulnerability in Apache APISIX. The attacker can completely bypass authentication capitalising on certain configurations of jwt-auth plugin. This issue affects Apache APISIX: from v2.2 through v3.16.0. Users are recommended to upgrade to version v3.17.0, which fixes the issue. | |
| Title | Apache APISIX: JWT Algorithm Confusion allows authentication bypass | |
| Weaknesses | CWE-290 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-06-22T16:17:30.194Z
Reserved: 2026-04-08T02:56:44.658Z
Link: CVE-2026-39999
Updated: 2026-06-22T16:17:24.557Z
Status : Analyzed
Published: 2026-06-19T14:16:21.950
Modified: 2026-06-23T15:08:22.603
Link: CVE-2026-39999
No data.
OpenCVE Enrichment
Updated: 2026-06-19T21:45:04Z