CVE-2026-81270
nicheUnauthenticated Information Disclosure via Search in Apache Allura (through 1.20.0)
Apache Allura, the open-source software forge platform, improperly exposes non-public information through its search functionality (CWE-200). Because the flaw is network-exploitable with no privileges or user interaction required, an unauthenticated remote attacker can submit search queries that retrieve content from restricted or private projects hosted on the forge. The attacker gains unauthorized read access to confidential/non-public data hosted in the affected instance, with no impact on integrity or availability (confidentiality-only impact, rated high at CVSS 7.5). All deployments running Allura through version 1.20.0 are affected; version 1.21.0 fixes the issue. There is no known exploitation in the wild, no public proof-of-concept, and EPSS puts 30-day exploitation probability at only 0.4%.
What to do: Upgrade Apache Allura to version 1.21.0. If an immediate upgrade is not possible, restrict unauthenticated access to the search functionality and audit search/query logs for signs that non-public project content was retrieved by unauthenticated users. Note that internet-exposed Allura instances are the primary concern given the no-authentication attack vector.
| Apache Allura | through 1.20.0 (fixed in 1.21.0) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Apache Allura: exposure of non-public information via search. This issue affects Apache Allura: through 1.20.0. Users are recommended to upgrade to version 1.21.0, which fixes the issue.
- Weakness
- CWE-200
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.