CVE-2025-32781: Apolloconfig Apollo
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior to 2.5.0, Apollo Portal does not verify application and namespace permissions when an authenticated user requests a release by ID through GET /envs/{env}/releases/{releaseId} while configView.memberOnly.envs is enabled, allowing a low-privileged Portal user who obtains or guesses a valid releaseId to read configuration data from other applications and namespaces without calling UserPermissionValidator.shouldHideConfigToCurrentUser(...). This issue is fixed in version 2.5.0.
Affected products
- Apolloconfig Apollo: before 2.5.0 (fixed in 2.5.0)
Published 2026-07-15. Last modified 2026-09-29.