ZeroHour

CVE-2026-81270

niche

Unauthenticated Information Disclosure via Search in Apache Allura (through 1.20.0)

CVSS 3.1
7.5 high
EPSS
<1%p32
Published
()
Modified
AI analysis

Apache Allura, the open-source software forge platform, improperly exposes non-public information through its search functionality (CWE-200). Because the flaw is network-exploitable with no privileges or user interaction required, an unauthenticated remote attacker can submit search queries that retrieve content from restricted or private projects hosted on the forge. The attacker gains unauthorized read access to confidential/non-public data hosted in the affected instance, with no impact on integrity or availability (confidentiality-only impact, rated high at CVSS 7.5). All deployments running Allura through version 1.20.0 are affected; version 1.21.0 fixes the issue. There is no known exploitation in the wild, no public proof-of-concept, and EPSS puts 30-day exploitation probability at only 0.4%.

What to do: Upgrade Apache Allura to version 1.21.0. If an immediate upgrade is not possible, restrict unauthenticated access to the search functionality and audit search/query logs for signs that non-public project content was retrieved by unauthenticated users. Note that internet-exposed Allura instances are the primary concern given the no-authentication attack vector.

Affected
Apache Allurathrough 1.20.0 (fixed in 1.21.0)
Estimated exposure
nichelikely tens to hundreds of self-hosted instances or fewer — Allura is a rarely-deployed, self-hosted Apache forge project with few known public installations beyond Apache's own infrastructure, so the install base is assumed small; no public scan or install-count metrics exist for it.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Apache Allura: exposure of non-public information via search. This issue affects Apache Allura: through 1.20.0. Users are recommended to upgrade to version 1.21.0, which fixes the issue.

Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.