Apache APISIX 3.17-3.18 SAML Signature Verification Flaw (CVE-2026-94212)
CVE-2026-94212 Published on October 1, 2026

Apache APISIX: unauthenticated impersonation issue in saml-auth
Improper verification of cryptographic signature vulnerability in Apache APISIX. Any unauthenticated attacker could impersonate any user on every route protected by the saml-auth plugin under default configuration. This issue affects Apache APISIX: from 3.17.0 through 3.18.0. Users are recommended to upgrade to version 3.19.0, which fixes the issue.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-94212 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
LOW
User Interaction:
NONE

Weakness Type

Improper Verification of Cryptographic Signature

The software does not verify, or incorrectly verifies, the cryptographic signature for data.


Products Associated with CVE-2026-94212

Want to know whenever a new CVE is published for Apache Apisix? stack.watch will email you.

 

Affected Versions

Apache Software Foundation Apache APISIX: