Improper Verification of Cryptographic Signature in Apache APISIX - CVE-2026-94212
Published: October 1, 2026
Vulnerability details
The vulnerability allows a remote user to impersonate any user.
The vulnerability exists due to improper verification of cryptographic signature in the saml-auth plugin when processing SAML authentication data. A remote user can provide SAML authentication data to impersonate any user.
Only routes protected by the saml-auth plugin under the default configuration are affected.