CVE WATCH / VULNERABILITY DETAIL

CVE-2026-94212

UNKNOWNCVSS 0NVD feed

Published 1 October 2026 · tracked since 2 October 2026

Description

Improper verification of cryptographic signature vulnerability in Apache APISIX.Any unauthenticated attacker could impersonate any user on every route protected by the saml-auth plugin under default configuration. This issue affects Apache APISIX: from 3.17.0 through 3.18.0.Users are recomme

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-94212 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-94212

UNKNOWNCVSS 0NVD feed

Published 1 October 2026 · tracked since 2 October 2026

Description

Improper verification of cryptographic signature vulnerability in Apache APISIX.Any unauthenticated attacker could impersonate any user on every route protected by the saml-auth plugin under default configuration. This issue affects Apache APISIX: from 3.17.0 through 3.18.0.Users are recomme

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]