CVE-2026-82379: Apache Roller: WSSE digest authentication headers can be replayed
Apache Roller 6.1.5 lets attackers replay captured WSSE digest headers to bypass AtomPub authentication.
CVE-2026-82379 is a capture-replay authentication bypass in Apache Roller 6.1.5, rated Moderate with a CVSS 3.1 score of 7.7. An attacker who captures a valid WSSE digest authentication header can replay it and gain the victim's AtomPub authority. Authentication does not enforce nonce uniqueness or timestamp freshness. The attack is network-based with high complexity, requires no privileges or user interaction, and has high confidentiality and integrity impact with low availability impact.
38