CVE-2026-39999Disclosure(apache / apisix)

LOWCVSS 9.1 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch apache apisix systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Authentication Bypass by Spoofing vulnerability in Apache APISIX. The attacker can completely bypass authentication capitalising on certain configurations of jwt-auth plugin. This issue affects Apache APISIX: from v2.2 through v3.16.0. Users are recommended to upgrade to version v3.17.0, which fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-290

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • apisix

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 9 signals
  • Disclosure: 6 classified signals
  • Peaked at 4 mentions on most recent observed day (2026-08-19)
  • 9 total mentions across 4 days

Affected systems

Vendors
Products
apisix

Deep dive

Activity timeline9 mentions / 4d
01234Mentions · 2026-06-21: 2Mentions · 2026-07-08: 1Mentions · 2026-07-09: 2Mentions · 2026-08-19: 4Patch / Workaround · 2026-06-21: 2Patch / Workaround · 2026-07-08: 1Patch / Workaround · 2026-07-09: 1Technical Details · 2026-06-21: 2Technical Details · 2026-07-08: 1Technical Details · 2026-07-09: 2Technical Details · 2026-08-19: 406-2107-0807-0908-19
Signal classification2 categories
Disclosure
666.7%
Patch
333.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-212
Disclosure1Patch1
2026-07-081
Patch1
2026-07-092
Disclosure1Patch1
2026-08-194
Disclosure4
Full discourse9 posts
  • ZoomEye@zoomeye_team
    Disclosure

    🚨 CVE-2026-39999: Apache APISIX: JWT Algorithm Confusion allows authentication bypass Critical Vulnerability Alert! APISIX is affected by CVE-2026-39999. Full Vulnerability Details & Analysis at DarkEye: 🔗 https://darkeye.org/vuln/cve/CVE-2026-39999 🔍 Identify Targets via ZoomEye: Filter: vul.cve="CVE-2026-39999" Search Dork: app="APISIX" Exposure: 30.1k instances identified globally. ZoomEye Search Link: 👉 https://www.zoomeye.ai/searchResult?q=YXBwPSJBUElTSVgi&t=all&utm_source=twitter&utm_medium=social&utm_campaign=cve_ops_20260709 #Infosec #CyberSecurity #ZoomEye #DarkEye

    Post summary

    The post announces a newly disclosed CVE-2026-39999 in Apache APISIX, describing a JWT algorithm confusion authentication bypass and listing affected instances, but it does not provide exploitation details or mitigation information.

    112020114.0K
    12.7K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    APISIX authentication bypass CVE-2026-39999 lets attackers forge JWTs via algorithm confusion. APISIX 3.16.0 is affected; upgrade to 3.16.1. #APISIX #ApacheAPISIX #JWT #AuthBypass #InfoSec http://securityonline.info/apisix-jwt-auth-bypass/

    Post summary

    APISIX authentication bypass (CVE‑2026‑39999) allows forging JWTs through algorithm confusion; upgrading to version 3.16.1 resolves the issue.

    00070559
    12.9K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Full Tweet 🚨 CVE-2026-39999: Apache APISIX: JWT Algorithm Confusion allows authentication bypass 0day Intel: 🚨 CVE-2026-39999: Apache APISIX: JWT Algorithm Confusion allows authentication

    Post summary

    The tweet announces the discovery of CVE-2026-39999, a JWT algorithm confusion vulnerability in Apache APISIX that permits authentication bypass, but does not provide proof‑of‑concept, exploit code, patch information, or evidence of active exploitation.

    1000034
    324 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Source: X search for CVE-2026 critical Posted: 2026-07-09T08:14:21.000Z Likes: 13 0day Intel: 🚨 CVE-2026-39999: Apache APISIX: JWT Algorithm Confusion allows authentication

    Post summary

    A tweet announces a critical CVE-2026-39999 vulnerability in Apache APISIX involving JWT algorithm confusion that could enable unauthorized authentication.

    1000041
    324 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-39999: 🚨 CVE-2026-39999: Apache APISIX: JWT Algorithm Confusion allows authentication bypass Critical Vulnerability Alert! APISIX is affected by CVE-2026-39999. Full Vulnerability Details & Analysis at DarkEye: 🔗 🔍 Identify Targets…

    Post summary

    The notice announces a critical CVE‑2026‑39999 flaw in Apache APISIX—specifically a JWT algorithm confusion that permits authentication bypass—without providing a PoC, exploit, patch, or claim of active exploitation.

    1000044
    324 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    0day Intel: 🚨 CVE-2026-39999: Apache APISIX: JWT Algorithm Confusion allows authentication

    Post summary

    A new CVE (CVE-2026-39999) has been disclosed for Apache APISIX, describing a JWT Algorithm Confusion vulnerability that allows authentication bypass.

    1000030
    324 followersView on X
  • ThreatWire@ThreatWire_
    Patch

    🚨 CVE-2026-39999: An Apache APISIX authentication bypass vulnerability could allow attackers to forge JWTs through algorithm confusion. Upgrade to v3.16.1. #CyberSecurity #CVE #APISIX #JWT #ThreatWire

    Post summary

    The post warns of CVE-2026‑39999, a JWT forging flaw in Apache APISIX, and urges users to upgrade to v3.16.1.

    0001077
    66 followersView on X
  • Can Artuc@canartuc
    Disclosure

    A bypass in Apache APISIX jwt-auth means a spoofed token could slip past your gateway. CVE-2026-39999 covers versions 2.2 through 3.16.0, a wide range that many production deployments fall inside. The fix is 3.17.0. Do you know which APISIX version your gateway runs right now?

    Post summary

    The post announces a JWT authentication bypass (CVE‑2026‑39999) in Apache APISIX versions 2.2‑3.16.0, with a fix available in 3.17.0, and urges checking your current deployment.

    0000037
    172 followersView on X
  • Can Artuc@canartuc
    Patch

    Apache APISIX patched CVE-2026-39999, an authentication-bypass-by-spoofing flaw in its jwt-auth plugin affecting versions 2.2 through 3.16.0. The fix lands in 3.17.0; the advisory claims CVSS v4.0 7.0. If jwt-auth guards your gateway, how fast can you reach 3.17.0?

    Post summary

    The advisory discloses an authentication-bypass flaw in APISIX’s jwt-auth plugin and announces a patch arriving in version 3.17.0, urging users to upgrade promptly.

    0000044
    172 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheapisix---

Explore more