Vulnerability DatabaseCVE-2026-102795

CVE-2026-102795: 
Apache Traffic Server vulnerability analysis and mitigation

Overview

CVE-2026-102795 is an Improper Access Control vulnerability in Apache Traffic Server (ATS) that allows unauthenticated remote attackers to bypass access controls and modify data or content processed by the server. It affects Apache Traffic Server versions 9.0.0 through 9.2.14 and 10.0.0 through 10.1.3. This CVE supersedes CVE-2026-41920, which incorrectly listed the affected 9.x range as 9.0.0–9.1.14; all 9.2.x releases prior to 9.2.15 are also affected. It was published on October 2, 2026, with a CVSS v3.1 base score of 9.3 (Critical) and a CVSS v4.0 base score of 7.0 (High) (GitHub Advisory, ENISA EUVD).

Technical details

The vulnerability is classified as CWE-284 (Improper Access Control), meaning the product fails to restrict or incorrectly restricts access to a resource from an unauthorized actor. Exploitation occurs over the network without requiring authentication, privileges, or user interaction, though the CVSS v4.0 scoring notes that certain attack requirements (deployment/execution conditions) must be present. The flaw enables an attacker to bypass authorization mechanisms within Apache Traffic Server, potentially manipulating traffic or content the proxy processes. No public technical write-up or proof-of-concept code detailing the specific exploitation mechanism has been published as of the disclosure date (GitHub Advisory, Apache Mailing List).

Impact

Successful exploitation allows an unauthenticated network attacker to bypass access controls and make unauthorized modifications to data or content processed by Apache Traffic Server. The primary impact is high integrity loss on systems downstream of the proxy (subsequent systems), with a secondary low confidentiality impact, as reflected in the CVSS v3.1 scoring (Integrity: High, Confidentiality: Low, scope changed). Because Apache Traffic Server commonly acts as a reverse proxy or caching layer for web infrastructure, a successful attack could allow content injection, cache poisoning, or manipulation of responses served to end users, potentially affecting a broad set of downstream clients and services (GitHub Advisory, ENISA EUVD).

Exploitability

As of the disclosure date, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (ENISA EUVD). The EPSS score is 0.0, indicating a currently low probability of exploitation in the near term. The vulnerability is rated as automatable by NVD SSVC analysis, meaning exploitation could be scripted without manual interaction. No threat actor attribution or CISA KEV catalog listing has been reported at this time.

Mitigation and workarounds

Apache Software Foundation has released patched versions addressing this vulnerability: upgrade to Apache Traffic Server 9.2.15 (for the 9.x branch) or 10.1.4 (for the 10.x branch). If immediate patching is not feasible, implement network-level access controls (e.g., firewall rules, IP allowlisting) to restrict access to the Apache Traffic Server instance and limit exposure to trusted sources only. Organizations should also review ATS access logs for anomalous or unauthorized requests as a precautionary measure (GitHub Advisory, Apache Mailing List).

Community reactions

The vulnerability received coverage from The Hacker Wire, which published an article highlighting the critical nature of the improper access control flaw and its potential to expose services (The Hacker Wire). A post on Bluesky from the infosec community noted the disclosure shortly after publication. General community sentiment reflects concern given the high CVSS v3.1 score and the broad deployment of Apache Traffic Server in production web infrastructure, though the absence of a public exploit has tempered urgency somewhat.

Additional resources


Source: This report was generated using AI

Related Apache Traffic Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-58188HIGH8.4
  • Apache Traffic Server logoApache Traffic Server
  • cpe:2.3:a:apache:traffic_server
NoYesJul 29, 2026
CVE-2026-58189HIGH8.2
  • Apache Traffic Server logoApache Traffic Server
  • trafficserver9
NoYesJul 29, 2026
CVE-2026-102795HIGH7
  • Apache Traffic Server logoApache Traffic Server
  • trafficserver
NoYesOct 02, 2026
CVE-2026-65100MEDIUM6.3
  • Apache Traffic Server logoApache Traffic Server
  • cpe:2.3:a:apache:traffic_server
NoYesJul 29, 2026
CVE-2026-58187MEDIUM6.3
  • Apache Traffic Server logoApache Traffic Server
  • trafficserver
NoYesJul 29, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management