CVE-2026-94212: Apache Software Foundation Apache APISIX

Medium severity, CVSS 6.4. EPSS: 0.3% chance of exploitation in the next 30 days.

Improper verification of cryptographic signature vulnerability in Apache APISIX. Any unauthenticated attacker could impersonate any user on every route protected by the saml-auth plugin under default configuration. This issue affects Apache APISIX: from 3.17.0 through 3.18.0. Users are recommended to upgrade to version 3.19.0, which fixes the issue.

Affected products

Published 2026-10-01. Last modified 2026-10-01.