Description
PoC-Apisix RCE via serverless-pre-function plugin when Admin API is exposed without authentication. Reported to cveform.mitre.org Vulnerability APISIX Admin API exposed without adminkeyrequired: true allows unauthenticated attackers to create routes...
Basic Information
ID
98FA3964-11CF-5394-BD6E-9ED7F7452844
Published
Jan 10, 2026 at 14:34