Junglewise Threat Intelligence

CVE-2026-59954: apolloconfig Apollo ConfigService authentication bypass via appId mismatch

CVE-2026-59954 · Severity: high · CVSS 7.5 · Published 2026-07-15

Technologies: com.ctrip.framework.apollo:apollo (Maven), ApolloConfig Apollo. Vendors: Maven, ApolloConfig.

Executive brief

Apollo is a configuration management system used to manage settings for microservices. A security flaw in the ConfigService component allows unauthorized users to bypass authentication and access sensitive configuration data. By using slightly modified application identifiers (such as adding spaces or accents), an attacker can trick the system into skipping security checks while still retrieving the protected configuration files.

Technical details

Apollo ConfigService prior to version 2.5.2 contains an authentication bypass vulnerability (CWE-287/CWE-20) affecting the /configs and /configfiles endpoints. When AccessKey or management key authentication is enabled, the service extracts the appId from the request to look up secrets; however, if a non-canonical variant is provided (e.g., trailing spaces or accent variants), the lookup fails to find a secret and may allow the request to proceed without signature verification. Because downstream database lookups often use collations (like PAD SPACE or accent-insensitive) that treat these variants as equivalent to the real appId, the attacker successfully retrieves the protected configuration. The issue is resolved in version 2.5.2 by strictly validating appId variants during the authentication phase.

Affected products

  • apolloconfig Apollo ConfigService < 2.5.2

Timeline

  • 2026-07-12: patched: Version 2.5.2 released
  • 2026-07-12: advisory: GitHub Security Advisory GHSA-4w3q-qpfq-v992 published
  • 2026-07-15: disclosed: CVE-2026-59954 published to NVD

References

Related threats