CVE-2026-44087 Details
Description
Insufficient Verification of Data Authenticity vulnerability in Apache APISIX. The openid-connect plugin under default configuration has an attack surface that allows the attacker to spoof identity headers allowing the attacker to get unauthorized access the protected resources. This issue affects Apache APISIX: from 2.3 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue.
A vulnerability allowing insufficient verification of data authenticity has been identified in Apache APISIX versions 2.3 through 3.16.0. The issue resides in the OpenID-Connect plugin, which, under default configuration, exposes an attack surface that enables spoofing of identity headers. This spoofing can lead to unauthorized access to protected resources.
Users are advised to upgrade to Apache APISIX version 3.17.0 or later, as this version addresses the vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/06/19/7 | CVE | Third Party Advisory |
| https://lists.apache.org/thread/72ryrgdssk6s2x9d6xn14bxyyl878xfm | [email protected] | Vendor AdvisoryMailing List |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-345 | Insufficient Verification of Data Authenticity | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache apisix | >= 2.3, < 3.17.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 23, 2026 | Initial Analysis | [email protected] |
| Jun 22, 2026 | CVE Modified | CISA-ADP |
| Jun 19, 2026 | CVE Modified | CVE |
| Jun 19, 2026 | New CVE Received | [email protected] |