PT-2026-103831 · Apache · Apache Apisix

·

CVE-2026-94212

·

Published

2026-10-01

·

Updated

2026-10-01

CVSS v4.0

6.4

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N
Improper verification of cryptographic signature vulnerability in Apache APISIX.
Any unauthenticated attacker could impersonate any user on every route protected by the saml-auth plugin under default configuration. This issue affects Apache APISIX: from 3.17.0 through 3.18.0.
Users are recommended to upgrade to version 3.19.0, which fixes the issue.

Fix

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94212

Affected Products

Apache Apisix