PatchSiren

apolloconfig CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM apolloconfig CVE published 2026-07-15

CVE-2025-32781

A low-privileged user can read configuration data from other applications and namespaces in Apollo Portal before version 2.5.0 due to insufficient permission verification. This issue arises when an authenticated user requests a release by ID through GET /envs/{env}/releases/{releaseId} while configView.memberOnly.envs is enabled, allowing unauthorized access to configuration data. Defenders and administra [truncated]