CyberRota
← Ana sayfaya dön

CVE-2026-49231

MEDIUM · CVSS 5.4 EPSS %0.36

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-06-19T14:16:23.543 · Çekilme zamanı: 2026-06-30T18:27:51.041161+00:00

CyberRota Yorumu

Detaylı analiz gerekiyor.

CVE
CVE-2026-49231
Severity
MEDIUM
CVSS
5.4
EPSS
%0.36
Apache

Orijinal NVD Açıklaması

Authentication Bypass by Spoofing vulnerability in opa plugin. An attacker could relay spoofed identity headers to upstream capitalising on non-default configuration in opa plugin. This could allow the attacker to assume higher privileges on the upstream service. This issue affects Apache APISIX: from 3.5.0 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue.