CVE-2026-82379: Apache Roller: WSSE digest authentication headers can be replayed
Apache Roller 6.1.5 lets attackers replay captured WSSE digest headers to bypass AtomPub authentication.
CVE-2026-82379 is a capture-replay authentication bypass in Apache Roller 6.1.5, rated Moderate with a CVSS 3.1 score of 7.7. An attacker who captures a valid WSSE digest authentication header can replay it and gain the victim's AtomPub authority. Authentication does not enforce nonce uniqueness or timestamp freshness. The attack is network-based with high complexity, requires no privileges or user interaction, and has high confidentiality and integrity impact with low availability impact.
- CVE-2026-82379 affects Apache Roller 6.1.5.
- Captured WSSE digest headers can be replayed for AtomPub access.
- Nonce uniqueness and timestamp freshness are not enforced.
- CVSS 3.1 is 7.7; the vendor rates it Moderate.
Vulnerabilities mentionedAll →
- published —
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-82379 | NVD description · AI analysis pending | — | — | — | — | — |
Posted by David M. Johnson on Sep 25 Severity: Moderate CVSS 3.1: 7.7 (high) CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L Affected versions: - Apache Roller 6.1.5 Description: Authentication Bypass by Capture-replay in Apache Roller 6.1.5 allows an attacker who captures a valid WSSE digest authentication header to replay it and gain the victim's AtomPub authority, because the authentication does not enforce nonce uniqueness or timestamp freshness. Only installations...
This source does not provide full text. Read it at seclists.org.