CVE-2026-94212: Apache APISIX: unauthenticated impersonation issue in saml-auth
Improper verification of cryptographic signature vulnerability in Apache APISIX.
Any unauthenticated attacker could impersonate any user on every route protected by the saml-auth plugin under default configuration. This issue affects Apache APISIX: from 3.17.0 through 3.18.0.
Users are recommended to upgrade to version 3.19.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache APISIXto a version that resolves this vulnerability.Fixed in 3.19.0
Event History
Frequently Asked Questions
Which deployments are affected?
Apache APISIX versions 3.17.0 through 3.18.0 are affected when routes are protected by the saml-auth plugin under its default configuration.
Does an attacker need credentials to exploit this issue?
No. An unauthenticated attacker could impersonate any user on routes protected by the saml-auth plugin under the default configuration.
What is the recommended remediation?
Upgrade Apache APISIX to version 3.19.0, which fixes the issue.