CVE Record
[ CRITICAL ]CVE-2026-82378
Apache Roller OAuth 1.0a Authorization Bypass Allows Token Theft
Incorrect authorization in Apache Roller 6.1.5 OAuth 1.0a endpoint lets an unauthenticated attacker obtain an access token for any user. CVSS 9.0 critical.
- Vendor
- Apache Software Foundation
- Product
- Apache Roller
- CVSS
- 9.0
- EPSS (exploit probability)
- 0.4%
- Status
- patched
- Published
CVE-2026-82378 is an incorrect authorization vulnerability in the OAuth 1.0a authorization endpoint of Apache Roller 6.1.5. An unauthenticated attacker who obtains an outstanding request token for a site-wide OAuth consumer can exploit the authorization endpoint to receive an access token for any user, bypassing the user-approval step that is supposed to gate that exchange.
What to do: Upgrade Apache Roller to a patched version. See the NVD record and the Apache Roller GitHub fix.
