CVE-2026-94212
Deferred
Deferred - Pending Action
Improper Cryptographic Signature Verification in Apache APISIX
Vulnerability report for CVE-2026-94212, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-01
Last updated on: 2026-10-01
Assigner: Apache Software Foundation
Description
Description
Improper verification of cryptographic signature vulnerability in Apache APISIX.
Any unauthenticated attacker could impersonate any user on every route protected by the saml-auth plugin under default configuration.Β This issue affects Apache APISIX: from 3.17.0 through 3.18.0.
Users are recommended to upgrade to version 3.19.0, which fixes the issue.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| apache | apisix | From 3.17.0 (inc) to 3.18.0 (inc) |
| apache | apisix | 3.19.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-347 | The product does not verify, or incorrectly verifies, the cryptographic signature for data. |