Apache Software FoundationCVE-2026-102795
Apache Traffic Server: improper access control
No fix yet
Improper Access Control vulnerability in Apache Traffic Server.
This issue affects Apache Traffic Server: from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.
This CVE supersedes CVE-2026-41920, whose record listed the affected 9.x versions as 9.0.0 through 9.1.14 and the fixed version as 9.1.15. All 9.2.x releases before 9.2.15 are affected.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Apache Traffic Server Product | >= 9.0.0, <= 9.2.14 | No fix yet |
| >= 10.0.0, <= 10.1.3 | No fix yet |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-284
More Apache Software Foundation advisories
All Apache Software Foundation| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 2 | Apache OpenOffice: code execution | High8.8 | 95923fd437e06edd38a4f0e139a27c755a6f3ba6+1 more |
| Oct 2 | Apache Thrift: improper exception handling | High8.7 | 0.25.0 |
| Oct 2 | Uncaught exception vulnerability in Apache Thrift Perl bindings | High8.2 | 0.25.0 |
| Oct 2 | Inefficient Algorithmic Complexity vulnerability in Apache Thrift Perl bindings | High8.2 | 0.25.0 |
| Oct 2 | Apache Thrift: uncontrolled recursion | High8.2 | 0.25.0 |
| Oct 2 | Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings | High8.7 | 0.25.0 |