Incorrect Authorization in Apache Roller Affects User Accounts
CVE-2026-82378

9CRITICAL

Key Information:

Vendor

Apache

Vendor
CVE Published:
28 September 2026

What is CVE-2026-82378?

The flaw in Apache Roller's OAuth 1.0a authorization endpoint allows an unauthenticated attacker to exploit an improper handling of request tokens. By leveraging knowledge of an outstanding request token from a site-wide consumer, the attacker can bind it to any user account, including administrative accounts, through an unsigned authorization request. This vulnerability specifically targets installations configured for OAuth 1.0a and can be mitigated by upgrading to Apache Roller version 6.1.6 or later, which enhances security by ensuring that authorization is linked to the authenticated session.

Affected Version(s)

Apache Roller 6.1.5

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

meifukun
.