CVE-2026-47341 Details
Description
Authentication Bypass by Capture-replay vulnerability in Apache APISIX. Attacker can benefit from certain configurations in hmac-auth to re-use a token forever, bypassing expiry. This issue affects Apache APISIX: from 3.11.0 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue.
A vulnerability allowing authentication bypass through capture-replay has been identified in Apache APISIX versions 3.11.0 prior to 3.16.0. This issue arises in certain HMAC authentication configurations, where an attacker can reuse a token indefinitely, circumventing its expiration. Users are advised to upgrade to version 3.17.0, which addresses this vulnerability.
Users should upgrade to Apache APISIX version 3.17.0 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/06/19/10 | CVE | Third Party Advisory |
| https://lists.apache.org/thread/ob6ng9x2hxtyfojs839hs1n0v18xxzf2 | [email protected] | Vendor AdvisoryMailing List |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-294 | Authentication Bypass by Capture-replay | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache apisix | >= 3.11.0, < 3.17.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 23, 2026 | Initial Analysis | [email protected] |
| Jun 22, 2026 | CVE Modified | CISA-ADP |
| Jun 19, 2026 | CVE Modified | CVE |
| Jun 19, 2026 | New CVE Received | [email protected] |