Improper access control in Apache Traffic Server - CVE-2026-58159

 

Improper access control in Apache Traffic Server - CVE-2026-58159

Published: August 24, 2026


Vulnerability identifier: #VU144774
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-58159
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass access controls.

The vulnerability exists due to improper access control in remap/ACL when handling UDS listeners and ACL matching. A remote attacker can exploit ACL matching errors to bypass access controls.

The advisory specifically mentions bypass of IP access controls on UDS listeners.


Affected software

Apache Traffic Server
Fedora
trafficserver

How to mitigate CVE-2026-58159

Install security update from vendor's website.

Apache Traffic Server - addressed in versions 9.2.14, 10.1.3
trafficserver - addressed in versions 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44

External References

Related Security Bulletins