ZeroHour

CVE-2026-73239

CVSS 3.1
6.5 medium
EPSS
<1%p27
Published
()
Modified
Description

Insecure Direct Object Reference (IDOR) due to missing permission checks for multiple Artifact types in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue.

Vendors
apache
Products
allura
Weakness
CWE-280, CWE-639
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.