Improper Access Control in Apache Traffic Server
CVE-2026-41920

7HIGH

Key Information:

Vendor

Apache

Vendor
CVE Published:
29 July 2026

What is CVE-2026-41920?

An improper access control vulnerability exists in Apache Traffic Server versions ranging from 9.0.0 to 9.1.14 and 10.0.0 to 10.1.3, allowing unauthorized access to sensitive features. Users should immediately upgrade to version 9.1.15 or 10.1.4 to mitigate this security risk and safeguard their systems.

Affected Version(s)

Apache Traffic Server 9.0.0 <= 9.1.14

Apache Traffic Server 10.0.0 <= 10.1.3

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

JD Marsters (Bhut Red)
Apache Community
.