
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-102795 is an Improper Access Control vulnerability in Apache Traffic Server (ATS) that allows unauthenticated remote attackers to bypass access controls and modify data or content processed by the server. It affects Apache Traffic Server versions 9.0.0 through 9.2.14 and 10.0.0 through 10.1.3. This CVE supersedes CVE-2026-41920, which incorrectly listed the affected 9.x range as 9.0.0–9.1.14; all 9.2.x releases prior to 9.2.15 are also affected. It was published on October 2, 2026, with a CVSS v3.1 base score of 9.3 (Critical) and a CVSS v4.0 base score of 7.0 (High) (GitHub Advisory, ENISA EUVD).
The vulnerability is classified as CWE-284 (Improper Access Control), meaning the product fails to restrict or incorrectly restricts access to a resource from an unauthorized actor. Exploitation occurs over the network without requiring authentication, privileges, or user interaction, though the CVSS v4.0 scoring notes that certain attack requirements (deployment/execution conditions) must be present. The flaw enables an attacker to bypass authorization mechanisms within Apache Traffic Server, potentially manipulating traffic or content the proxy processes. No public technical write-up or proof-of-concept code detailing the specific exploitation mechanism has been published as of the disclosure date (GitHub Advisory, Apache Mailing List).
Successful exploitation allows an unauthenticated network attacker to bypass access controls and make unauthorized modifications to data or content processed by Apache Traffic Server. The primary impact is high integrity loss on systems downstream of the proxy (subsequent systems), with a secondary low confidentiality impact, as reflected in the CVSS v3.1 scoring (Integrity: High, Confidentiality: Low, scope changed). Because Apache Traffic Server commonly acts as a reverse proxy or caching layer for web infrastructure, a successful attack could allow content injection, cache poisoning, or manipulation of responses served to end users, potentially affecting a broad set of downstream clients and services (GitHub Advisory, ENISA EUVD).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (ENISA EUVD). The EPSS score is 0.0, indicating a currently low probability of exploitation in the near term. The vulnerability is rated as automatable by NVD SSVC analysis, meaning exploitation could be scripted without manual interaction. No threat actor attribution or CISA KEV catalog listing has been reported at this time.
Apache Software Foundation has released patched versions addressing this vulnerability: upgrade to Apache Traffic Server 9.2.15 (for the 9.x branch) or 10.1.4 (for the 10.x branch). If immediate patching is not feasible, implement network-level access controls (e.g., firewall rules, IP allowlisting) to restrict access to the Apache Traffic Server instance and limit exposure to trusted sources only. Organizations should also review ATS access logs for anomalous or unauthorized requests as a precautionary measure (GitHub Advisory, Apache Mailing List).
The vulnerability received coverage from The Hacker Wire, which published an article highlighting the critical nature of the improper access control flaw and its potential to expose services (The Hacker Wire). A post on Bluesky from the infosec community noted the disclosure shortly after publication. General community sentiment reflects concern given the high CVSS v3.1 score and the broad deployment of Apache Traffic Server in production web infrastructure, though the absence of a public exploit has tempered urgency somewhat.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."