Description
Improper verification of cryptographic signature vulnerability in Apache APISIX.



Any unauthenticated attacker could impersonate any user on every route protected by the saml-auth plugin under default configuration. This issue affects Apache APISIX: from 3.17.0 through 3.18.0.



Users are recommended to upgrade to version 3.19.0, which fixes the issue.
Published: 2026-10-01
Score: 6.4 Medium
EPSS: n/a
KEV: No
Impact: Unauthenticated Impersonation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from improper verification of a cryptographic signature in Apache APISIX’s saml-auth plugin. Because the default configuration fails to validate the SAML response, an attacker who can provide a crafted request can impersonate any user on all routes protected by the plugin without needing valid credentials. This allows the attacker to act with full privileges of the impersonated user, compromising confidentiality and integrity of protected data.

Affected Systems

Apache Software Foundation: Apache APISIX is impacted for all releases from 3.17.0 through 3.18.0 when the saml-auth plugin is enabled using its default configuration. No other products or versions are explicitly listed as affected.

Risk and Exploitability

The CVSS score of 6.4 indicates a moderate to high severity vulnerability. The EPSS score is not available, and the risk is not listed in the CISA KEV catalog, so the likelihood of widespread exploitation is unclear; however, the flaw requires no authentication and a simple crafted request, making it easily exploitable in environments where the plugin is enabled. Attackers can leverage this flaw to impersonate users and carry out any action permitted to those users on every protected route.

Generated by OpenCVE AI on October 1, 2026 at 13:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache APISIX to version 3.19.0, which contains the fix for the signature verification issue.
  • If an upgrade is not immediately possible, disable or remove the saml-auth plugin from all routes that do not require it.
  • Configure the saml-auth plugin to enforce strict signature validation and validate the issuer, audience, and timestamp of SAML responses to prevent forgery attempts.

Generated by OpenCVE AI on October 1, 2026 at 13:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
References

Thu, 01 Oct 2026 11:30:00 +0000

Type Values Removed Values Added
Description Improper verification of cryptographic signature vulnerability in Apache APISIX. Any unauthenticated attacker could impersonate any user on every route protected by the saml-auth plugin under default configuration. This issue affects Apache APISIX: from 3.17.0 through 3.18.0. Users are recommended to upgrade to version 3.19.0, which fixes the issue.
Title Apache APISIX: unauthenticated impersonation issue in saml-auth
Weaknesses CWE-347
References
Metrics cvssV4_0

{'score': 6.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-01T14:52:48.202Z

Reserved: 2026-09-21T05:44:07.039Z

Link: CVE-2026-94212

cve-icon Vulnrichment

Updated: 2026-10-01T13:10:59.699Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T12:17:16.793

Modified: 2026-10-01T15:17:35.967

Link: CVE-2026-94212

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T13:30:06Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature