Exposure of Data Element to Wrong Session in Apache APISIX - CVE-2026-82806
Published: October 1, 2026
Vulnerability details
The vulnerability allows a remote user to obtain unintended authorization.
The vulnerability exists due to improper session data isolation in authz-keycloak authorization scope handling when processing requests on the same route. A remote user can send requests on the same route to cause authorization scopes to persist into later requests and obtain unintended authorization.
The issue occurs under a supported authz-keycloak configuration.