CVE-2026-82378: Apache Roller: OAuth authorization endpoint trusts request-supplied identity
Apache Roller 6.1.5 OAuth lets attackers bind a known request token to any account, including an administrator.
CVE-2026-82378 is an incorrect-authorization flaw in the OAuth 1.0a authorization endpoint of Apache Roller 6.1.5. An unauthenticated remote attacker who learns an outstanding request token for a configured site-wide consumer can bind that token to an arbitrary account, including an administrator. CVSS 3.1 is 9.0 (AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H), although the project labeled the issue Moderate. The attack has high complexity and changed scope, with high impacts on confidentiality, integrity, and availability; in-the-wild exploitation is not reported.
50