PT-2026-82088 · Apache · Apache Apisix

·

CVE-2026-63041

·

Published

2026-08-26

·

Updated

2026-08-28

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache APISIX versions 3.11.0 through 3.17.0
Description An issue exists where the attach-consumer-label plugin fails to correctly sanitize certain input values. This allows an attacker to perform an authorization bypass or escalate privileges by providing untrusted inputs that influence security decisions.
Recommendations Upgrade to version 3.18.0.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-APISIX-2026-63041
CVE-2026-63041

Affected Products

Apache Apisix