Critical severity9.3NVD Advisory· Published Oct 2, 2026· Updated Oct 2, 2026
CVE-2026-102795
CVE-2026-102795
Description
Improper Access Control vulnerability in Apache Traffic Server.
This issue affects Apache Traffic Server: from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.
This CVE supersedes CVE-2026-41920, whose record listed the affected 9.x versions as 9.0.0 through 9.1.14 and the fixed version as 9.1.15. All 9.2.x releases before 9.2.15 are affected.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.