CVE-2026-41920 | Apache Traffic Server up to 9.1.14/10.1.3 access control (EUVD-2026-50167 / WID-SEC-2026-2561)
A vulnerability was found in Apache Traffic Server up to 9.1.14/10.1.3. It has been declared as very critical. The affected element is an unknown function. Executing a manipulation can lead to improper access controls.
This vulnerability is tracked as CVE-2026-41920. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.