CVE-2026-102795: Apache Traffic Server fixes affected version range
This text was generated using artificial intelligence (AI).For Apache Traffic Server, the vulnerability was published on October 2, 2026. CVE-2026-102795 It is classified as Improper Access Control according to CWE-284 and replaces CVE-2026-41920.
Affected are Apache Traffic Server in the versions 9.0.0 to 9.2.14 as well as 10.0.0 to 10.1.3.. As fixed releases, the Apache Software Foundation names 9.2.15 for the 9.x product line and 10.1.4 for the 10.x product line.
The vulnerability receives a CVSS score of 9.3. . The published CVSS string is. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:N.
. This allows an attack over the network without prior permissions or interaction by users. The entry also indicates a potential change in the scope.
CVE-2026-102795 replaces CVE-2026-41920. The previous entry listed an affected range for the 9.x product line from 9.0.0 to 9.1.14, with version 9.1.15 as a fix.
The new entry expands the check to all 9.2.x releases prior to 9.2.15. Organizations that prioritized based on CVE-2026-41920 should re-evaluate their Apache Traffic Server instances in the 9.x line against the corrected range.
Technical Classification
The vulnerability affects access control in Apache Traffic Server. The underlying mechanism documented for CVE-2026-41920 relates to the enforcement of a policy for SNI and Host Header mapping.
At the time of publication, no active exploitation of CVE-2026-102795 is known.
The following points are particularly relevant for the technical assessment:
Assign Apache Traffic Server instances to the deployed product lines 9.x or 10.x.
Compare installed versions with the affected version ranges.
Prioritize externally accessible systems.
Check the SNI-to-Host-Header matching configuration and set it restrictively.
Define responsibilities and maintenance windows for updates.
Patch planning by product line
The Apache Software Foundation recommends upgrading to 9.2.15 or 10.1.4. The target version depends on the deployed product line:
Update 9.x line systems to version 9.2.15.
Update 10.x line systems to version 10.1.4.
Prioritize and mitigate affected systems.
Check patch status and exposure for CVE-2026-102795.
The correction of the version range directly affects the technical inventory. An inventory that does not capture 9.2.x instances does not consider all affected releases mentioned in the current entry.
For organizations falling under the NIS-2 directive — implemented nationally in Germany and Austria — timely patching of exposed network components is one of the required security measures to document. In Switzerland, corresponding requirements apply based on the revised Information Security Act (ISG) and the reporting obligation to BACS. Organizations with personal data on affected systems should also check whether there is a reporting obligation under Art. 33 GDPR within 72 hours in the event of a compromise.
LocateRisk: Visibility of externally accessible instances
Apache Traffic Server can be operated as an externally accessible service under a domain or IP address. LocateRisk can identify publicly accessible Apache Traffic Server instances and use them to compare against the affected version range.
The external visibility of an instance does not replace verification of the installed version. Therefore, for prioritizing CVE-2026-102795, the visible systems should be linked to internal information regarding product line, version, and patch status.
In vendor risk management, tracking critical vulnerabilities in software vendors can complement the technical assessment. For Apache Traffic Server, the immediate check point is the own externally accessible instances and their assignment to the affected versions.
Am I affected?
Affected is Apache Traffic Server in the versions mentioned above; the vulnerability was fixed in 9.2.15, 10.1.4. Those who want to know if Apache Traffic Server is even visible in their own externally accessible infrastructure can do so by CVE Quick Check Use the tool at the end of this article: It shows exposed systems and the software that is visible from the outside.
It is not always possible to determine the specific version that has been installed from the outside—the key factor is comparing it with the manufacturer's advisory.
This affects all versions of the 9.x line from 9.0.0 to 9.2.14 inclusive, as well as all versions of the 10.x line from 10.0.0 to 10.1.3 inclusive. The fixed releases are 9.2.15 and 10.1.4.
CVE-2026-41920 listed only versions up to 9.1.14 as affected for the 9.x product line and named 9.1.15 as the fix. CVE-2026-102795 corrects this area and includes all 9.2.x releases prior to 9.2.15. Organizations that prioritized based on CVE-2026-41920 should update their inventory accordingly.
As of the publication date on October 2, 2026, there is no known active exploitation of CVE-2026-102795. The CVSS score of 9.3 reflects the technical damage potential and justifies timely patch planning regardless of the current exploit status.
Status: October 02, 2026. This post is for general informational purposes and is not legal, security, or action advice in individual cases. The IT security situation and patch availability may have changed since publication; the linked vendor advisory is always authoritative. Despite careful research, we do not guarantee the timeliness, correctness, and completeness.
CVE Quick Check
In just a few minutes, check whether there are any indications of a current CVE on your externally visible attack surface.
A rough estimate in just a few minutes via email.
Learn more during a free consultation with a LocateRisk consultant.
You'll receive this by email
companyYour Company, LLC
Verified CVECVE-2026-102795
Passive Assessment
Information About the CVEfound or not found
Want to find out more, book a demo or simply exchange ideas? We look forward to hearing from you!
We use cookies to optimize our website and our service.
Functional
Always active
Technical storage or access is strictly necessary for the lawful purpose of enabling the use of a particular service expressly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a message over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that have not been requested by the subscriber or user.
Statistics
The technical storage or access, which is carried out exclusively for statistical purposes.Technical storage or access used solely for anonymous statistical purposes. Without a subpoena, the voluntary consent of your Internet service provider, or additional records from third parties, information stored or accessed for this purpose alone generally cannot be used to identify you.
Marketing
Technical storage or access is necessary to create user profiles, to send advertisements, or to track the user on a website or across multiple websites for similar marketing purposes.