CVE-2026-94269: CWE-647 Use of Non-Canonical URL paths for authorization decisions in Apache Software Foundation Apache APISIX
Use of Non-Canonical URL paths for authorization decisions vulnerability in Apache APISIX. In some configurations where a permissive route overlaps a protected one, a crafted encoded path can reach an upstream endpoint that the matched route's policies were never meant to cover. A request that should have been rejected is served instead, giving unauthenticated access to a protected upstream endpoint. This issue affects Apache APISIX: from 2.14.1 through 3.18.0. Users are recommended to upgrade to version 3.19.0, which fixes the issue.
AI Analysis
Technical Summary
This vulnerability arises when Apache APISIX is configured with overlapping permissive and protected routes. An attacker can craft encoded URL paths that match a permissive route but reach an upstream endpoint intended to be protected by another route's policies. This results in unauthorized access to protected resources. The flaw affects Apache APISIX versions >=2.14.1 and <=3.18.0. The vendor has released version 3.19.0 to address this issue.
Potential Impact
An attacker can gain unauthenticated access to upstream endpoints that should be protected by route policies. This bypasses intended authorization controls, potentially exposing sensitive services or data. The CVSS 4.0 score is 6.3 (medium severity), reflecting network attack vector, low complexity, no privileges or user interaction required, and limited scope and impact.
Mitigation Recommendations
Users should upgrade Apache APISIX to version 3.19.0 or later, where this vulnerability is fixed. No other mitigations are indicated by the vendor advisory.
CVE-2026-94269: CWE-647 Use of Non-Canonical URL paths for authorization decisions in Apache Software Foundation Apache APISIX
Description
Use of Non-Canonical URL paths for authorization decisions vulnerability in Apache APISIX. In some configurations where a permissive route overlaps a protected one, a crafted encoded path can reach an upstream endpoint that the matched route's policies were never meant to cover. A request that should have been rejected is served instead, giving unauthenticated access to a protected upstream endpoint. This issue affects Apache APISIX: from 2.14.1 through 3.18.0. Users are recommended to upgrade to version 3.19.0, which fixes the issue.
CVSS v4.0
Score 6.3medium
Affected software
Apache Software Foundation
Apache APISIX
pkg:github/apache/apisixRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability arises when Apache APISIX is configured with overlapping permissive and protected routes. An attacker can craft encoded URL paths that match a permissive route but reach an upstream endpoint intended to be protected by another route's policies. This results in unauthorized access to protected resources. The flaw affects Apache APISIX versions >=2.14.1 and <=3.18.0. The vendor has released version 3.19.0 to address this issue.
Potential Impact
An attacker can gain unauthenticated access to upstream endpoints that should be protected by route policies. This bypasses intended authorization controls, potentially exposing sensitive services or data. The CVSS 4.0 score is 6.3 (medium severity), reflecting network attack vector, low complexity, no privileges or user interaction required, and limited scope and impact.
Mitigation Recommendations
Users should upgrade Apache APISIX to version 3.19.0 or later, where this vulnerability is fixed. No other mitigations are indicated by the vendor advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- apache
- Date Reserved
- 2026-09-21T09:15:23.527Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6abe748da43b0b3b89bd1c9c
Added to database: 10/01/2026, 14:56:13 UTC
Last enriched: 10/01/2026, 15:20:03 UTC
Last updated: 10/01/2026, 19:41:32 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.