CVE-2026-94212
UNKNOWN
NVD
CVSS Score
0
Severity
UNKNOWN
Published
Oct 01, 2026
Vendor
unknown
Description
Improper verification of cryptographic signature vulnerability in Apache APISIX. Any unauthenticated attacker could impersonate any user on every route protected by the saml-auth plugin under default configuration.Β This issue affects Apache APISIX: from 3.17.0 through 3.18.0. Users are recommended to upgrade to version 3.19.0, which fixes the issue.