Junglewise Threat Intelligence

CVE-2026-59955: Apollo ConfigService authentication bypass in raw configuration endpoint

CVE-2026-59955 · Severity: high · CVSS 7.5 · Published 2026-07-15

Technologies: com.ctrip.framework.apollo:apollo (Maven), ApolloConfig Apollo. Vendors: Maven, ApolloConfig.

Executive brief

Apollo is a configuration management system used to manage settings for microservices. A security flaw in the ConfigService component allows unauthorized users to bypass authentication and access raw configuration data. This could lead to the exposure of sensitive application secrets, database credentials, or internal system settings, potentially compromising the entire microservice environment.

Technical details

An authentication bypass exists in Apollo ConfigService's handling of requests to the '/configfiles/raw/{appId}/{clusterName}/{namespace}' endpoint. The vulnerability stems from the service incorrectly parsing the string 'raw' as the appId for authentication purposes instead of extracting the actual appId from the URI path. Because the system looks up AccessKey secrets for the literal appId 'raw', it may find no associated secrets and proceed without requiring a valid signature, even if the target appId in the path requires authentication. An unauthenticated remote attacker can exploit this to retrieve raw configuration files. The issue is addressed in version 2.5.2 by ensuring the correct appId is validated during the authentication process.

Affected products

  • ApolloConfig Apollo ConfigService < 2.5.2

Timeline

  • 2026-07-12: patched: Version 2.5.2 released
  • 2026-07-15: disclosed: NVD publication date

References

Related threats