Incorrect Authorization in Apache Roller Affects User Accounts
CVE-2026-82378
9CRITICAL
What is CVE-2026-82378?
The flaw in Apache Roller's OAuth 1.0a authorization endpoint allows an unauthenticated attacker to exploit an improper handling of request tokens. By leveraging knowledge of an outstanding request token from a site-wide consumer, the attacker can bind it to any user account, including administrative accounts, through an unsigned authorization request. This vulnerability specifically targets installations configured for OAuth 1.0a and can be mitigated by upgrading to Apache Roller version 6.1.6 or later, which enhances security by ensuring that authorization is linked to the authenticated session.
Affected Version(s)
Apache Roller 6.1.5