AUGUST 28, 2026
Live Feed
Back to database
Case File

CVE-2026-63041

HIGH · CVSS 8.8 EPSS 0.46%

Source: NVD + CISA KEV + EPSS · Published 2026-08-26 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

Apache APISIX versions 3.11.0 through 3.17.0 are vulnerable to a privilege escalation and authorization bypass due to improper sanitization of untrusted inputs in the attach-consumer-label plugin. This could allow attackers to manipulate security decisions, potentially compromising the integrity of the system. Organizations using affected versions should prioritize upgrading to version 3.18.0 to mitigate this risk.

CVE
CVE-2026-63041
Severity
HIGH
CVSS
8.8
EPSS
0.46%
Apache

Original NVD Description

Reliance on Untrusted Inputs in a Security Decision vulnerability in Apache APISIX. This vulnerability allows an attacker to escalate privilege or perform an authorization bypass by sending certain values that the attach-consumer-label plugin does not sanitise correctly. This issue affects Apache APISIX: from 3.11.0 through 3.17.0. Users are recommended to upgrade to version 3.18.0, which fixes the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)