CVE-2026-49230
Improper Validation of Integrity Check Value vulnerability in Apache APISIX. The jwe-decrypt plugin under default configuration is vulnerable to authentication bypass. This issue affects Apache APISIX: from 3.8.0 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
- EPSS probability
- 0.30%
- CWE
- CWE-354
- Published
- 2026-06-19
- Last modified
- 2026-06-22
Affected products
- Apache Software Foundation Apache APISIX
Weakness type
Related vulnerabilities
- CVE-2026-72929 — Windows Installer Elevation of Privilege Vulnerability
- CVE-2026-20354 — Cisco Secure Email S/MIME Ciphertext Decryption Vulnerabilty
- CVE-2026-82549 — Linux Foundation Magma SecurityModeComplete integrity check
- CVE-2026-75803 — AEAD Forgeries with Empty Ciphertext When Using EVP_Cipher()
- CVE-2026-75625 — Kraken Agents Peer-to-Peer Download Cache Poisoning via Digest Verification Bypass
- CVE-2026-12817 — OpenPGP AEAD decryption skips final tag on chunk-aligned data
- CVE-2026-12816 — IESEngine stream-mode MAC forgery via length-dependent KDF split
- CVE-2026-12803 — KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery)