Authentication Bypass Vulnerability in Apache Roller by Apache
CVE-2026-82379
7.7HIGH
What is CVE-2026-82379?
A vulnerability in Apache Roller 6.1.5 allows attackers to bypass authentication through the replay of captured WSSE digest authentication headers. This occurs due to the lack of nonce uniqueness or timestamp freshness in the authentication mechanism. Specifically, this affects installations that enable the AtomPub API with WSSE authentication and plaintext-compatible password storage. Users are advised to upgrade to Apache Roller 6.1.6 or later, as this version removes WSSE as a valid AtomPub authentication method. For existing installations, administrators must select a supported authentication method to ensure security.
Affected Version(s)
Apache Roller 6.1.5