CVE WATCH / VULNERABILITY DETAIL

CVE-2026-94276

UNKNOWNCVSS 0NVD feed

Published 1 October 2026 · tracked since 2 October 2026

Description

Improper Authentication vulnerability in Apache APISIX.On a route using openid-connect plugin with remote introspection against an authorization server that serves multiple issuers, a token that introspects as active for one issuer may get accepted on a route restricted to another. This issue affe

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-94276 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-94276

UNKNOWNCVSS 0NVD feed

Published 1 October 2026 · tracked since 2 October 2026

Description

Improper Authentication vulnerability in Apache APISIX.On a route using openid-connect plugin with remote introspection against an authorization server that serves multiple issuers, a token that introspects as active for one issuer may get accepted on a route restricted to another. This issue affe

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]