High severity8.8NVD Advisory· Published Aug 26, 2026· Updated Aug 27, 2026
CVE-2026-63041
CVE-2026-63041
Description
Reliance on Untrusted Inputs in a Security Decision vulnerability in Apache APISIX.
This vulnerability allows an attacker to escalate privilege or perform an authorization bypass by sending certain values that the attach-consumer-label plugin does not sanitise correctly.
This issue affects Apache APISIX: from 3.11.0 through 3.17.0.
Users are recommended to upgrade to version 3.18.0, which fixes the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
2- www.openwall.com/lists/oss-security/2026/08/26/11nvdMailing ListThird Party Advisory
- lists.apache.org/thread/yg9tgn699rz7kyglw82m1775do8frjr4nvdMailing ListVendor Advisory
News mentions
1- Apache: 25 Vulnerabilities Across Tomcat, Camel, Hive, and More Disclosed Aug 24-26Vypr Intelligence · Aug 26, 2026