Junglewise Threat Intelligence

CVE-2026-41920: Apache Traffic Server improper access control

CVE-2026-41920 · Severity: critical · CVSS 9.3 · Published 2026-07-29

Technologies: Apache Traffic Server. Vendors: Apache.

Executive brief

Apache Traffic Server, a high-performance caching proxy used to manage web traffic and speed up content delivery, contains a critical security flaw. This vulnerability allows unauthorized users to bypass access controls, potentially leading to the unauthorized modification of data or the circumvention of security policies. Organizations using affected versions should update immediately to prevent attackers from compromising the integrity of their web traffic management.

Technical details

An improper access control vulnerability (CWE-284) exists in Apache Traffic Server versions 9.0.0 through 9.1.14 and 10.0.0 through 10.1.3. The flaw allows a remote, unauthenticated attacker to bypass intended access restrictions via the network. According to the CVSS 3.1 score of 9.3, the vulnerability has a high impact on integrity and can lead to a scope change, suggesting it may affect downstream systems or the proxy's core security boundaries. The issue is resolved in versions 9.1.15 and 10.1.4.

Affected products

  • Apache Traffic Server 9.0.0 through 9.1.14, 10.0.0 through 10.1.3

Timeline

  • 2026-07-29: disclosed
  • 2026-07-29: advisory

References

Related threats