Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.0

CVE-2026-82378: Apache Roller lets attacker link token to any user

CVE-2026-82378 · published 12 days ago
Summary

If your Roller site uses a site‑wide OAuth connection, an attacker who discovers a pending request token can attach that token to any user account, even an administrator. This means the attacker could act as that user without proper login. Upgrade Roller to version 6.1.6 or newer to have the token tied to the logged‑in session and stop the risk.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
apache software foundation apache roller 6.1.5
Original advisory text
Apache Roller: OAuth authorization endpoint trusts request-supplied identity
Incorrect Authorization in the OAuth 1.0a authorization endpoint of Apache Roller 6.1.5 allows an unauthenticated remote attacker who learns an outstanding request token for a configured site-wide consumer to bind that token to an arbitrary user account, including an administrator, by submitting an unsigned authorization request. The endpoint derives the authorizing identity from a request-supplied value rather than the authenticated session. Only installations that configure an OAuth 1.0a site-wide consumer are affected, and exploitation requires knowledge of one of its outstanding request tokens. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which binds authorization to the logged-in session.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.0 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-863Incorrect Authorization
Timeline
Published28 Sep 2026
Updated9 Oct 2026
First seen28 Sep 2026
Sources
CVE-2026-82378 · MITRE
Track software like this
Free during beta