CVE-2026-82806: Apache APISIX: cross-request permission pollution via static permission list mutation
Exposure of data element to wrong session vulnerability in Apache APISIX.
This issue affects Apache APISIX: from 2.3.0 before 3.7.0.
Under a supported authz-keycloak configuration, a request's authorization scope could persist into later requests on the same route, leading to unintended authorization expansion and inconsistent access-control decisions.
Users are recommended to upgrade to version 3.7.0 or higher, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache APISIXto a version that resolves this vulnerability.Fixed in 3.7.0
Event History
Frequently Asked Questions
Which deployments are exposed?
Apache APISIX deployments from 2.3.0 before 3.7.0 are affected when using a supported authz-keycloak configuration. The issue is relevant where authorization scopes are used to control access on routes.
What conditions are required for unauthorized access decisions to occur?
A request's authorization scope must persist into later requests handled on the same route. This can cause those later requests to receive unintended authorization expansion or inconsistent access-control decisions.
What should administrators do to remediate the issue?
Upgrade Apache APISIX to version 3.7.0 or higher, which fixes the issue.