CVE-2026-102795

LOWCVSS 7.0 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue. This CVE supersedes CVE-2026-41920, whose record listed the affected 9.x versions as 9.0.0 through 9.1.14 and the fixed version as 9.1.15. All 9.2.x releases before 9.2.15 are affected.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-03: 110-03
Referenced assets1 URL
By indicator
Full discourse1 post
  • zoomeyebot@zoomeyebot

    🚨 Apache Traffic Server CVE-2026-102795: SNI-to-Host access control not enforced Critical Vulnerability Alert! Apache Traffic Server 9.0.0 through 9.2.14 and 10.0.0 through 10.1.3 is affected by CVE-2026-102795. 🔍 Identify Targets via ZoomEye: Search Dork: app="Apache Traffic Server" Exposure: 311.5k instances identified globally. ZoomEye Search Link: 👉 https://www.zoomeye.ai/searchResult?q=YXBwPSJBcGFjaGUgVHJhZmZpYyBTZXJ2ZXIi #Apache #TrafficServer #CVE #ZoomEye #AccessControl

    0001047
    25 followersView on X

Explore more