Com.ctrip.framework.apollo:apollo: CWE-20: Improper Input Validation in apolloconfig apollo (CVE-2026-59954)
Apollo ConfigService versions prior to 2.5.2 have an improper input validation vulnerability that may allow unauthorized access to configuration data when AccessKey or management key authentication is enabled. The issue arises because ConfigService accepts non-canonical appId variants during authentication, which downstream request handling resolves to protected applications. This includes variants with accent-insensitive collations or trailing spaces on the /configs and /configfiles endpoints. The vulnerability is fixed in version 2.5.2.
AI Analysis
Technical Summary
Apollo is a configuration management system used in microservice environments. Versions before 2.5.2 of Apollo ConfigService are vulnerable to improper input validation (CWE-20) and authentication bypass issues (CWE-287) because the service accepts non-canonical appId variants during authentication. This allows an attacker to bypass AccessKey or management key authentication by using appId variants such as those differing only by accents or trailing spaces under certain collation rules. As a result, unauthorized access to configuration data on the /configs and /configfiles endpoints is possible. The vulnerability is addressed in Apollo version 2.5.2.
Potential Impact
An attacker can gain unauthorized read access to configuration data protected by AccessKey or management key authentication by exploiting the acceptance of non-canonical appId variants. This leads to a confidentiality breach of sensitive configuration information. There is no indication of integrity or availability impact. The CVSS v3.1 base score is 7.5 (High), reflecting network attack vector, low attack complexity, no privileges required, no user interaction, and high confidentiality impact.
Mitigation Recommendations
Upgrade Apollo ConfigService to version 2.5.2 or later, where this vulnerability is fixed. No other mitigations are indicated or required by the vendor advisory. Patch status is confirmed fixed in 2.5.2.
Com.ctrip.framework.apollo:apollo: CWE-20: Improper Input Validation in apolloconfig apollo (CVE-2026-59954)
Description
Apollo ConfigService versions prior to 2.5.2 have an improper input validation vulnerability that may allow unauthorized access to configuration data when AccessKey or management key authentication is enabled. The issue arises because ConfigService accepts non-canonical appId variants during authentication, which downstream request handling resolves to protected applications. This includes variants with accent-insensitive collations or trailing spaces on the /configs and /configfiles endpoints. The vulnerability is fixed in version 2.5.2.
CVSS v3.1
Score 7.5high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Apollo is a configuration management system used in microservice environments. Versions before 2.5.2 of Apollo ConfigService are vulnerable to improper input validation (CWE-20) and authentication bypass issues (CWE-287) because the service accepts non-canonical appId variants during authentication. This allows an attacker to bypass AccessKey or management key authentication by using appId variants such as those differing only by accents or trailing spaces under certain collation rules. As a result, unauthorized access to configuration data on the /configs and /configfiles endpoints is possible. The vulnerability is addressed in Apollo version 2.5.2.
Potential Impact
An attacker can gain unauthorized read access to configuration data protected by AccessKey or management key authentication by exploiting the acceptance of non-canonical appId variants. This leads to a confidentiality breach of sensitive configuration information. There is no indication of integrity or availability impact. The CVSS v3.1 base score is 7.5 (High), reflecting network attack vector, low attack complexity, no privileges required, no user interaction, and high confidentiality impact.
Mitigation Recommendations
Upgrade Apollo ConfigService to version 2.5.2 or later, where this vulnerability is fixed. No other mitigations are indicated or required by the vendor advisory. Patch status is confirmed fixed in 2.5.2.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-4w3q-qpfq-v992
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-59954"]
- Ecosystems
- ["Maven"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6a55ffb268715ace432fa73e
Added to database: 07/14/2026, 09:21:54 UTC
Last enriched: 07/21/2026, 17:35:33 UTC
Last updated: 09/02/2026, 10:38:00 UTC
Views: 98
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.