Authentication Bypass Vulnerability in Apache Roller by Apache
CVE-2026-82379

7.7HIGH

Key Information:

Vendor

Apache

Vendor
CVE Published:
28 September 2026

What is CVE-2026-82379?

A vulnerability in Apache Roller 6.1.5 allows attackers to bypass authentication through the replay of captured WSSE digest authentication headers. This occurs due to the lack of nonce uniqueness or timestamp freshness in the authentication mechanism. Specifically, this affects installations that enable the AtomPub API with WSSE authentication and plaintext-compatible password storage. Users are advised to upgrade to Apache Roller 6.1.6 or later, as this version removes WSSE as a valid AtomPub authentication method. For existing installations, administrators must select a supported authentication method to ensure security.

Affected Version(s)

Apache Roller 6.1.5

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

meifukun
.