PatchSiren cyber security CVE debrief
CVE-2026-39998 Apache Software Foundation CVE debrief
CVE-2026-39998 is a MEDIUM-severity Improper Input Validation vulnerability in Apache APISIX, affecting versions from 2.12.0 through 3.16.0. An attacker can exploit certain configurations in the forward-auth plugin to spoof identity headers. Users should upgrade to version 3.17.0 to fix the issue. This vulnerability has a CVSS score of 5.8 and was published on June 19, 2026.
- Vendor
- Apache Software Foundation
- Product
- Apache APISIX
- CVSS
- MEDIUM 5.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-19
- Original CVE updated
- 2026-06-23
- Advisory published
- 2026-06-19
- Advisory updated
- 2026-06-23
Who should care
Defenders of Apache APISIX installations, particularly those using versions between 2.12.0 and 3.16.0, should be aware of this vulnerability. Upgrading to version 3.17.0 is recommended to mitigate the risk of identity header spoofing.
Technical summary
The CVE-2026-39998 vulnerability in Apache APISIX arises from improper input validation in the forward-auth plugin. This allows attackers to spoof identity headers under certain configurations. The vulnerability affects Apache APISIX versions from 2.12.0 to 3.16.0. The CVSS vector is CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X, indicating a Medium severity with a score of 5.8.
Defensive priority
Medium priority due to potential for header spoofing with CVSS score of 5.8
Recommended defensive actions
- Inventory Apache APISIX installations to identify affected versions.
- Review and upgrade vulnerable Apache APISIX instances to version 3.17.0.
- Monitor for unusual identity header activity.
- Implement compensating controls to validate identity headers.
- Review forward-auth plugin configurations for potential vulnerabilities.
Evidence notes
The primary evidence for CVE-2026-39998 comes from the NVD and CVE.org records. The vulnerability affects Apache APISIX versions 2.12.0 through 3.16.0. Defenders should verify their APISIX versions and configurations to assess exposure.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-39998 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-39998
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-39998 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-39998
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://lists.apache.org/thread/vgkvy396010d7g6m0jrn4d3hjf2svlvv
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.