CVE-2026-94276

CVE-2026-94276 published: Improper Authentication vulnerability in Apache APISIX. On a route using openid-connect plugin with remote introspection against an authorization server that serves multiple issuers, a token that introspects as active for one issuer may get accepted on a r...

View full NVD advisory → ← Back to CVE watch