Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.0
CVE-2026-82378: Apache Roller lets attacker link token to any user
CVE-2026-82378 · published 12 days ago
Summary
If your Roller site uses a site‑wide OAuth connection, an attacker who discovers a pending request token can attach that token to any user account, even an administrator. This means the attacker could act as that user without proper login. Upgrade Roller to version 6.1.6 or newer to have the token tied to the logged‑in session and stop the risk.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| apache software foundation | apache roller | 6.1.5 |
Original advisory text
Apache Roller: OAuth authorization endpoint trusts request-supplied identity
Incorrect Authorization in the OAuth 1.0a authorization endpoint of Apache Roller 6.1.5 allows an unauthenticated remote attacker who learns an outstanding request token for a configured site-wide consumer to bind that token to an arbitrary user account, including an administrator, by submitting an unsigned authorization request. The endpoint derives the authorizing identity from a request-supplied value rather than the authenticated session. Only installations that configure an OAuth 1.0a site-wide consumer are affected, and exploitation requires knowledge of one of its outstanding request tokens. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which binds authorization to the logged-in session.
References
- https://github.com/apache/roller/pull/165
- https://lists.apache.org/thread/fq512gy70zj9yx8v4c4zm54x43wqb04b
- http://www.openwall.com/lists/oss-security/2026/09/25/11
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82378... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-82378 Vendor Advisory
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-863Incorrect Authorization
Timeline
Published28 Sep 2026
Updated9 Oct 2026
First seen28 Sep 2026
Track software like this
Free during beta