CVE-2026-94212

LOWCVSS 6.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper verification of cryptographic signature vulnerability in Apache APISIX. Any unauthenticated attacker could impersonate any user on every route protected by the saml-auth plugin under default configuration. This issue affects Apache APISIX: from 3.17.0 through 3.18.0. Users are recommended to upgrade to version 3.19.0, which fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-347

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-08: 110-08
Referenced assets1 URL
Full discourse1 post
  • LinuxSecurity@lnxsec

    A gateway can enforce authentication on every route and still pass the wrong identity downstream. That is the uncomfortable part of CVE-2026-94212. In affected Apache APISIX deployments, the saml-auth plugin can accept an unauthenticated attacker as another user under the default configuration. The failure is not simply "the login page was bypassed." It is that applications behind the gateway may receive an identity they have been designed to trust. That changes the incident-response question. Finding malicious requests is useful, but teams also need to determine which downstream services treated gateway-supplied identity as authoritative and what those identities were allowed to do. **In practical terms, it is a good time to:** - inventory APISIX 3.17.0 and 3.18.0 instances and identify routes using `saml-auth` - trace which upstream applications consume identity attributes supplied after gateway authentication - compare access logs from APISIX with application authorization logs for unexpected user identities - move affected gateways to APISIX 3.19.0 and validate SAML authentication behavior after the upgrade How many internal applications could independently detect that the identity arriving from their trusted gateway was false? #LinuxSecurity #APISIX #Authentication #DevSecOps #InfrastructureSecurity https://linuxsecurity.com/news/security-vulnerabilities/apisix-api-gateway-security-user-impersonation

    0000063
    4.5K followersView on X

Explore more