Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.0

CVE-2026-41920: Apache Traffic Server: Malicious sites can impersonate trusted sites

CVE-2026-41920 · published 2 months ago
Summary

Apache Traffic Server versions 9.0.0 through 9.1.14 and 10.0.0 through 10.1.3 have a security issue. This means a malicious website can pretend to be a trusted site, potentially tricking users into revealing sensitive information. To fix this, update to version 9.1.15 or 10.1.4.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
Ecosystem VendorProductAffected versions
– apache software foundation apache traffic server <= 9.1.14
Debian:11 debian trafficserver All versions
Debian:12 debian trafficserver All versions
Ubuntu:16.04:LTS canonical trafficserver All versions
Ubuntu:18.04:LTS canonical trafficserver All versions
Ubuntu:Pro:20.04:LTS canonical trafficserver All versions
Ubuntu:Pro:22.04:LTS canonical trafficserver All versions
Ubuntu:24.04:LTS canonical trafficserver All versions
Original advisory text
Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade t...
Improper Access Control vulnerability in Apache Traffic Server.

This issue affects Apache Traffic Server: from 9.0.0 through 9.1.14, from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 9.1.15 or 10.1.4, which fixes the issue.
Severity
7.0 High
CVSS 3.1: 9.3 (MITRE)
CVSS 4.0: 7.5 (OSV)
CVSS 3.1: 9.3 (OSV)
Exploitation
EPSS <1%
Type
CWE-284Improper Access Control
Timeline
Published29 Jul 2026
Updated27 Sep 2026
First seen29 Jul 2026
Track software like this
Free during beta