Authorization Bypass in Apache APISIX Plugin
CVE-2026-63041
5.3MEDIUM
What is CVE-2026-63041?
A security vulnerability in Apache APISIX arises from the attach-consumer-label plugin's failure to properly sanitize input values. This oversight enables attackers to bypass authorization controls and potentially escalate privileges. Affected versions include Apache APISIX from 3.11.0 through 3.17.0. Users are strongly advised to upgrade to version 3.18.0 or later to mitigate against these risks.
Affected Version(s)
Apache APISIX 3.11.0 <= 3.17.0