Improper Verification of Cryptographic Signature in Apache APISIX
CVE-2026-94212

6.4MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
1 October 2026

What is CVE-2026-94212?

A vulnerability exists in Apache APISIX due to improper verification of cryptographic signatures. This flaw allows an unauthenticated attacker to impersonate any user on all routes protected by the saml-auth plugin in the product's default configuration. Users of Apache APISIX versions 3.17.0 through 3.18.0 are strongly advised to upgrade to version 3.19.0 to mitigate this risk.

Affected Version(s)

Apache APISIX 3.17.0 <= 3.18.0

References

CVSS V4

Score:
6.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

LucasFutures
shreemaan-abhishek
shreemaan-abhishek
.