CVE-2026-82378: Apache Roller: OAuth authorization endpoint trusts request-supplied identity
Apache Roller 6.1.5 OAuth lets attackers bind a known request token to any account, including an administrator.
CVE-2026-82378 is an incorrect-authorization flaw in the OAuth 1.0a authorization endpoint of Apache Roller 6.1.5. An unauthenticated remote attacker who learns an outstanding request token for a configured site-wide consumer can bind that token to an arbitrary account, including an administrator. CVSS 3.1 is 9.0 (AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H), although the project labeled the issue Moderate. The attack has high complexity and changed scope, with high impacts on confidentiality, integrity, and availability; in-the-wild exploitation is not reported.
- CVE-2026-82378 affects the Apache Roller 6.1.5 OAuth 1.0a endpoint.
- A known request token can be bound to any user, including an administrator.
- CVSS 3.1 is 9.0 with changed scope; the vendor rates it Moderate.
- The attack is unauthenticated but requires high complexity and a live request token.
Vulnerabilities mentionedAll →
- published —
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-82378 | NVD description · AI analysis pending | — | — | — | — | — |
Posted by David M. Johnson on Sep 25 Severity: Moderate CVSS 3.1: 9.0 (critical) CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H Affected versions: - Apache Roller 6.1.5 Description: Incorrect Authorization in the OAuth 1.0a authorization endpoint of Apache Roller 6.1.5 allows an unauthenticated remote attacker who learns an outstanding request token for a configured site-wide consumer to bind that token to an arbitrary user account, including an administrator, by submitting...
This source does not provide full text. Read it at seclists.org.