CVE-2026-48895: Apisix Unconditional Admin Route Bind
Unconditional binding of Admin API routes directly from core configuration detected. In Apache APISIX, this may inadvertently expose ETCD-backed routes when running in standalone (YAML) mode, leading to authentication bypass or deserialization exploits if default unauthenticated states are triggered. Ensure that routes enforce configuration provider segregat
greprules fetch cve-2026-48895-apisix-unconditional-admin-route-bind --engine opengrepDescription
Unconditional binding of Admin API routes directly from core configuration detected. In Apache APISIX, this may inadvertently expose ETCD-backed routes when running in standalone (YAML) mode, leading to authentication bypass or deserialization exploits if default unauthenticated states are triggered. Ensure that routes enforce configuration provider segregat
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.