
A gateway can enforce authentication on every route and still pass the wrong identity downstream. That is the uncomfortable part of CVE-2026-94212. In affected Apache APISIX deployments, the saml-auth plugin can accept an unauthenticated attacker as another user under the default configuration. The failure is not simply "the login page was bypassed." It is that applications behind the gateway may receive an identity they have been designed to trust. That changes the incident-response question. Finding malicious requests is useful, but teams also need to determine which downstream services treated gateway-supplied identity as authoritative and what those identities were allowed to do. **In practical terms, it is a good time to:** - inventory APISIX 3.17.0 and 3.18.0 instances and identify routes using `saml-auth` - trace which upstream applications consume identity attributes supplied after gateway authentication - compare access logs from APISIX with application authorization logs for unexpected user identities - move affected gateways to APISIX 3.19.0 and validate SAML authentication behavior after the upgrade How many internal applications could independently detect that the identity arriving from their trusted gateway was false? #LinuxSecurity #APISIX #Authentication #DevSecOps #InfrastructureSecurity https://linuxsecurity.com/news/security-vulnerabilities/apisix-api-gateway-security-user-impersonation
