CVE WATCH / VULNERABILITY DETAIL
CVE-2026-94276
UNKNOWNCVSS 0NVD feed
Published 1 October 2026 · tracked since 2 October 2026
Description
Improper Authentication vulnerability in Apache APISIX.On a route using openid-connect plugin with remote introspection against an authorization server that serves multiple issuers, a token that introspects as active for one issuer may get accepted on a route restricted to another. This issue affe
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog