Skip to content
feed: live
>_0dayNews
CVE Record
[ CRITICAL ]CVE-2026-82378

Apache Roller OAuth 1.0a Authorization Bypass Allows Token Theft

Incorrect authorization in Apache Roller 6.1.5 OAuth 1.0a endpoint lets an unauthenticated attacker obtain an access token for any user. CVSS 9.0 critical.

cat cve-2026-82378.json
Vendor
Apache Software Foundation
Product
Apache Roller
CVSS
9.0
EPSS (exploit probability)
0.4%
Status
patched
Published

CVE-2026-82378 is an incorrect authorization vulnerability in the OAuth 1.0a authorization endpoint of Apache Roller 6.1.5. An unauthenticated attacker who obtains an outstanding request token for a site-wide OAuth consumer can exploit the authorization endpoint to receive an access token for any user, bypassing the user-approval step that is supposed to gate that exchange.

What to do: Upgrade Apache Roller to a patched version. See the NVD record and the Apache Roller GitHub fix.