Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.0
CVE-2026-41920: Apache Traffic Server: Malicious sites can impersonate trusted sites
CVE-2026-41920 · published 2 months ago
Summary
Apache Traffic Server versions 9.0.0 through 9.1.14 and 10.0.0 through 10.1.3 have a security issue. This means a malicious website can pretend to be a trusted site, potentially tricking users into revealing sensitive information. To fix this, update to version 9.1.15 or 10.1.4.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | apache software foundation | apache traffic server | <= 9.1.14 |
| Debian:11 | debian | trafficserver | All versions |
| Debian:12 | debian | trafficserver | All versions |
| Ubuntu:16.04:LTS | canonical | trafficserver | All versions |
| Ubuntu:18.04:LTS | canonical | trafficserver | All versions |
| Ubuntu:Pro:20.04:LTS | canonical | trafficserver | All versions |
| Ubuntu:Pro:22.04:LTS | canonical | trafficserver | All versions |
| Ubuntu:24.04:LTS | canonical | trafficserver | All versions |
Original advisory text
Improper Access Control vulnerability in Apache Traffic Server.
This issue affects Apache Traffic Server: from 9.0.0 through 9.1.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade t...
Improper Access Control vulnerability in Apache Traffic Server.
This issue affects Apache Traffic Server: from 9.0.0 through 9.1.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.1.15 or 10.1.4, which fixes the issue.
This issue affects Apache Traffic Server: from 9.0.0 through 9.1.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.1.15 or 10.1.4, which fixes the issue.
References
- https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d vendor-advisory
- https://ubuntu.com/security/CVE-2026-41920 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-41920 Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2026-41920 Vendor Advisory
Severity
7.0
High
CVSS 3.1: 9.3 (MITRE)
CVSS 4.0: 7.5 (OSV)
CVSS 3.1: 9.3 (OSV)
Exploitation
EPSS <1%
Type
CWE-284Improper Access Control
Timeline
Published29 Jul 2026
Updated27 Sep 2026
First seen29 Jul 2026
Sources
DEBIAN-CVE-2026-41920 · OSV
CVE-2026-41920 · NVD
CVE-2026-41920 · MITRE
UBUNTU-CVE-2026-41920 · OSV
Track software like this
Free during beta