Description
Exposure of data element to wrong session vulnerability in Apache APISIX.



This issue affects Apache APISIX: from 2.3.0 before 3.7.0.



Under a supported authz-keycloak configuration, a request's authorization scope could persist into later requests on the same route, leading to unintended authorization expansion and inconsistent access-control decisions.



Users are recommended to upgrade to version 3.7.0 or higher, which fixes the issue.
Published: 2026-10-01
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Authorization Bypass via Permission Pollution
Action: Patch
AI Analysis

Impact

A state leakage flaw in Apache APISIX allows a request's authorization scope to persist into subsequent requests on the same API route, effectively expanding the permissions available to an attacker. The bug stems from a static permission list mutation that is not reset between requests, violating consistent access‑control enforcement and granting unauthorized access to protected resources. This weakness is catalogued as CWE-488, indicating that privileges are incorrectly retained across transaction boundaries.

Affected Systems

Apache APISIX versions from 2.3.0 up to, but not including, 3.7.0 are affected. The flaw manifests only when the authz‑keycloak plugin is enabled in supported configurations, exposing the gateway to unintended authorization expansion on any route accessed by a client.

Risk and Exploitability

The CVSS score of 5.3 denotes moderate severity; the EPSS score is not available, implying no documented exploitation but potential for abuse. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote attacker that can send HTTP requests to the APISIX gateway to trigger the permission persistence, enabling privilege escalation without additional privileges. The flaw requires server‑side changes and is mitigated by updating the software.

Generated by OpenCVE AI on October 1, 2026 at 14:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Apache APISIX 3.7.0 or later, which removes the permission list mutation bug.
  • After upgrading, restart the APISIX service to load the new version and ensure the fix is active.
  • Verify that the authz‑keycloak plugin re‑initializes permissions on each request, for example by testing that two consecutive requests from the same client no longer share scopes or by reviewing plugin logs for residual permissions.

Generated by OpenCVE AI on October 1, 2026 at 14:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
References

Thu, 01 Oct 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache apache Apisix
Vendors & Products Apache
Apache apache Apisix

Thu, 01 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description Exposure of data element to wrong session vulnerability in Apache APISIX. This issue affects Apache APISIX: from 2.3.0 before 3.7.0. Under a supported authz-keycloak configuration, a request's authorization scope could persist into later requests on the same route, leading to unintended authorization expansion and inconsistent access-control decisions. Users are recommended to upgrade to version 3.7.0 or higher, which fixes the issue.
Title Apache APISIX: cross-request permission pollution via static permission list mutation
Weaknesses CWE-488
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Apache Apache Apisix
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-01T14:57:12.282Z

Reserved: 2026-08-31T04:34:45.853Z

Link: CVE-2026-82806

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-01T11:17:28.190

Modified: 2026-10-01T15:17:32.303

Link: CVE-2026-82806

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T14:45:10Z

Weaknesses
  • CWE-488

    Exposure of Data Element to Wrong Session