Improper Verification of Cryptographic Signature in Apache APISIX
CVE-2026-94212
6.4MEDIUM
What is CVE-2026-94212?
A vulnerability exists in Apache APISIX due to improper verification of cryptographic signatures. This flaw allows an unauthenticated attacker to impersonate any user on all routes protected by the saml-auth plugin in the product's default configuration. Users of Apache APISIX versions 3.17.0 through 3.18.0 are strongly advised to upgrade to version 3.19.0 to mitigate this risk.
Affected Version(s)
Apache APISIX 3.17.0 <= 3.18.0
References
CVSS V4
Score:
6.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
LucasFutures
shreemaan-abhishek
shreemaan-abhishek