Medium severityNVD Advisory· Published Oct 1, 2026· Updated Oct 1, 2026
CVE-2026-82806
CVE-2026-82806
Description
Exposure of data element to wrong session vulnerability in Apache APISIX.
This issue affects Apache APISIX: from 2.3.0 before 3.7.0.
Under a supported authz-keycloak configuration, a request's authorization scope could persist into later requests on the same route, leading to unintended authorization expansion and inconsistent access-control decisions.
Users are recommended to upgrade to version 3.7.0 or higher, which fixes the issue.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.