CVE-2026-32621

CRITICAL

Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Prior to 2.9.6, 2.10.5, 2.11.6, 2.12.3, and 2.13.2, a vulnerability exists in query plan execution within...

Affects 0 products across 3 vendors.

BCS6.21
CVSS 3.19.9
EPSS0.5%
Percentile41th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, low privileges required, no user interaction needed, can impact systems beyond the vulnerable component, full confidentiality impact, full integrity impact.
CWE Weakness Definitions
CWE-1321: CWE-1321
Related Attack Patterns (CAPEC)
CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs
via CWE-1321
CAPEC-77 Manipulating User-Controlled Variables
via CWE-1321
CAPEC-180 Exploiting Incorrectly Configured Access Control Security Levels
via CWE-1321

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A vulnerability in Apollo Federation prior to specific versions allows for Object.prototype pollution through crafted query operations, potentially leading to remote code execution.

BSID: BS-2026-GLOBAL-082028-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-32621?
A vulnerability in Apollo Federation prior to specific versions allows for Object.prototype pollution through crafted query operations, potentially leading to remote code execution.
What is the CVSS score for CVE-2026-32621?
CVE-2026-32621 has CVSS 9.9 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L. EPSS: 0.5%.
Is CVE-2026-32621 actively exploited?
No confirmed active exploitation of CVE-2026-32621 as of 2026-05-30.
How do I remediate CVE-2026-32621?
Priority: IMMEDIATE.
What systems are affected by CVE-2026-32621?
CVE-2026-32621 affects: Client, Gateway, Target.
Vulnerability Details
CVE IDCVE-2026-32621
BSIDBS-2026-GLOBAL-082028-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
Published2026-03-16
Last Modified2026-04-28
ICS Relevance0%
Weakness (CWE)
SourceNVD
Official Description

Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Prior to 2.9.6, 2.10.5, 2.11.6, 2.12.3, and 2.13.2, a vulnerability exists in query plan execution within the gateway that may allow pollution of Object.prototype in certain scenarios. A malicious client may be able to pollute Object.prototype in gateway directly by crafting operations with field aliases and/or variable names that target prototype-inheritable properties. Alternatively, if a subgraph were to be compromised by a malicious actor, they may be able to pollute Object.prototype in gateway by crafting JSON response payloads that target prototype-inheritable properties. This vulnerability is fixed in 2.9.6, 2.10.5, 2.11.6, 2.12.3, and 2.13.2.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

A malicious client can exploit this vulnerability by crafting GraphQL operations with specific field aliases, which can lead to pollution of the Object.prototype in the gateway's execution environment.

Exploitation Likelihood: HIGH

Affected Products
VendorProductFixed Version
Client —
Gateway —
Target —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 144 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash0c2e195f42cd889bf101fc08495e060c530714b84955f566dd1ea95ec5cce66a47322ba0ed9b58f1a1a213fce4de1a1d8b5a6752e09994b4826744f80c7985a4
Related CVEs affecting Client
CVE-1999-0661 10.0 A system is running a version of software that was replaced with a Trojan Hor... CVE-2025-53624 10.0 The Docusaurus gists plugin adds a page to your Docusaurus instance, displayi... CVE-2025-6512 10.0 On a client with a non-admin user, a script can be integrated into a report. ... CVE-2026-23693 10.0 ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elemen... CVE-2026-41070 10.0 openvpn-auth-oauth2 is a plugin/management interface client for OpenVPN serve...
View all Client CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.9 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →