CVE WATCH / VULNERABILITY DETAIL
CVE-2026-82806
UNKNOWNCVSS 0NVD feed
Published 1 October 2026 · tracked since 2 October 2026
Description
Exposure of data element to wrong session vulnerability in Apache APISIX.This issue affects Apache APISIX: from 2.3.0 before 3.7.0.Under a supported authz-keycloak configuration, a request's authorization scope could persist into later requests on the same route, leading to unintended author
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog