Vulnerability Description
Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue. This CVE supersedes CVE-2026-41920, whose record listed the affected 9.x versions as 9.0.0 through 9.1.14 and the fixed version as 9.1.15. All 9.2.x releases before 9.2.15 are affected.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread.html/qcxzvcbbln68hd0j08pdnjdj4r991nhd
- https://www.cve.org/CVERecord?id=CVE-2026-41920
FAQ
What is CVE-2026-102795?
CVE-2026-102795 is a vulnerability with a CVSS score of 9.3 (CRITICAL). Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade ...
How severe is CVE-2026-102795?
CVE-2026-102795 has been rated CRITICAL with a CVSS base score of 9.3/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-102795?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.