PT-2025-28065 · Apache · Apache Apisix

Benoit Tellier

·

Published

2025-04-02

·

Updated

2025-07-16

·

CVE-2025-27446

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Apache APISIX(java-plugin-runner) versions 0.2.0 through 0.5.0
Description: The issue is related to incorrect permission assignment for critical resources in the Apache APISIX java-plugin-runner, allowing a local attacker to elevate privileges due to local listening file permissions.
Recommendations: For Apache APISIX(java-plugin-runner) versions 0.2.0 through 0.5.0, upgrade to version 0.6.0 or higher to fix the issue.

Fix

Incorrect Permission

Weakness Enumeration

Related Identifiers

BDU:2026-00212
BIT-APISIX-2025-27446
CVE-2025-27446

Affected Products

Apache Apisix