CVE-2026-82806
Received Received - Intake

Session Fixation in Apache APISIX

Vulnerability report for CVE-2026-82806, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: Apache Software Foundation

Description

Exposure of data element to wrong session vulnerability in Apache APISIX. This issue affects Apache APISIX: from 2.3.0 before 3.7.0. Under a supported authz-keycloak configuration, a request's authorization scope could persist into later requests on the same route, leading to unintended authorization expansion and inconsistent access-control decisions. Users are recommended to upgrade to version 3.7.0 or higher, which fixes the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
apache apisix From 2.3.0 (inc) to 3.7.0 (exc)
apache apisix 3.7.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-488 The product does not sufficiently enforce boundaries between the states of different sessions, causing data to be provided to, or used by, the wrong session.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves exposure of data elements to the wrong session in Apache APISIX. It affects versions from 2.3.0 before 3.7.0. Under a specific authz-keycloak configuration, a request's authorization scope could carry over to later requests on the same route, causing unintended authorization expansion and inconsistent access control decisions.

Detection Guidance

Detecting this vulnerability requires checking Apache APISIX versions and authz-keycloak configurations. Verify if your APISIX version is between 2.3.0 and 3.6.0. Inspect authz-keycloak plugin settings for improper scope persistence in requests.

Impact Analysis

The vulnerability could lead to unauthorized access to resources or data if an attacker exploits the persistent authorization scope. This may result in privilege escalation or data exposure, depending on the configuration and environment.

Compliance Impact

This vulnerability could compromise compliance with data protection regulations like GDPR or HIPAA by allowing unauthorized access to sensitive data. Inconsistent access control decisions may lead to violations of confidentiality and integrity requirements.

Mitigation Strategies

Upgrade Apache APISIX to version 3.7.0 or higher to fix the vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82806. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart