Junglewise Threat Intelligence

CVE-2025-32781: Apollo Portal Authorization Bypass in Release Controller

CVE-2025-32781 · Severity: medium · CVSS 6.5 · Published 2026-07-15

Technologies: com.ctrip.framework.apollo:apollo (Maven). Vendors: ApolloConfig, Maven.

Executive brief

Apollo Portal, a configuration management system for microservices, contains a security flaw where authenticated users can view sensitive configuration data they are not authorized to see. By guessing or obtaining a specific release ID, a low-privileged user can bypass permission checks to access configuration details from other applications or namespaces. This could lead to the exposure of sensitive business data, credentials, or service endpoints.

Technical details

A missing authorization check (CWE-862) exists in the Apollo Portal 'ReleaseController' component. When the 'configView.memberOnly.envs' setting is enabled, the 'GET /envs/{env}/releases/{releaseId}' endpoint fails to invoke 'UserPermissionValidator.shouldHideConfigToCurrentUser' before returning data. An authenticated attacker with network access can exploit this by providing a valid 'releaseId' for an application or namespace they do not have permissions for, resulting in an Insecure Direct Object Reference (IDOR) that discloses configuration details. The vulnerability is resolved in version 2.5.0 by adding the necessary permission validation logic.

Affected products

  • apolloconfig Apollo Portal < 2.5.0

Timeline

  • 2025-04-11: patched: Fix commit and pull request merged into master branch.
  • 2026-07-12: advisory: GitHub Security Advisory published.
  • 2026-07-15: disclosed: CVE published to NVD.

References

Related threats