
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-63041 is an authorization bypass and privilege escalation vulnerability in Apache APISIX caused by the attach-consumer-label plugin's failure to sanitize client-supplied consumer-label headers (CWE-807: Reliance on Untrusted Inputs in a Security Decision). It affects Apache APISIX versions 3.11.0 through 3.17.0, and was publicly disclosed on August 25–26, 2026 via the Apache security mailing list and oss-security. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) and a CVSS v4.0 base score of 5.3 (Medium) (Apache Advisory, GitHub Advisory, oss-security).
The root cause is classified as CWE-807 (Reliance on Untrusted Inputs in a Security Decision): the attach-consumer-label plugin in Apache APISIX does not strip or sanitize consumer-label headers supplied by clients before using them in security decisions. An attacker with low-level authenticated access can craft HTTP requests containing manipulated consumer-label header values that the plugin passes through without validation, allowing the attacker to impersonate higher-privileged consumers or bypass authorization controls enforced by downstream plugins or routes. No special configuration or complex preconditions are required beyond having a valid low-privilege account; the attack is network-accessible and requires no user interaction (Apache Advisory, oss-security).
Successful exploitation allows an authenticated low-privilege attacker to escalate privileges or bypass authorization controls within Apache APISIX, potentially gaining access to resources, APIs, or administrative functions they are not authorized to use. While the vulnerable system's direct confidentiality and integrity impact is rated None in CVSS v4.0, subsequent systems (downstream services protected by APISIX) face low-to-moderate confidentiality and integrity risks due to the authorization bypass. In environments where APISIX acts as an API gateway protecting sensitive backend services, this could enable unauthorized data access or modification across multiple downstream systems (GitHub Advisory, Apache Advisory).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time, as confirmed by NVD SSVC assessment (exploitation: none) and Feedly threat intelligence (GitHub Advisory). The EPSS score is approximately 0.677%, indicating a relatively low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
attach-consumer-label plugin enabled on one or more routes, using network scanning or API gateway fingerprinting techniques.X-Consumer-Username: admin or a label corresponding to a higher-privileged consumer group) that the attach-consumer-label plugin would normally set based on authenticated consumer identity.X-Consumer-Username, X-Consumer-Groups, or custom label headers) set by the client rather than by APISIX itself; requests from low-privilege consumers accessing high-privilege or administrative endpoints.Upgrade Apache APISIX to version 3.18.0, which resolves the issue by ensuring the attach-consumer-label plugin strips client-supplied consumer-label headers before making security decisions (Apache Advisory). If immediate patching is not feasible, restrict network access to APISIX instances to trusted clients only, and limit the privileges of service accounts to reduce the blast radius of a potential bypass. Additionally, consider disabling the attach-consumer-label plugin on sensitive routes until the upgrade can be applied.
The vulnerability was reported by security researcher tonghuaroot and disclosed via the Apache oss-security mailing list on August 26, 2026 (oss-security). Social media activity was limited, with brief mentions on Bluesky infosec accounts shortly after disclosure. No major vendor statements beyond the Apache advisory or significant media coverage have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."