Apache ShenYu, an asynchronous, high-performance, cross-language, responsive API gateway from the Apache Foundation, is vulnerable to authorization issues in versions prior to Apache ShenYu 2.5.1. The vulnerability stems from the presence of improper privilege management, which could be exploited by a low-privilege attacker to create users with higher privileges than their own.