CVE Record
[ HIGH ]CVE-2026-82379
Apache Roller WSSE Auth Bypass via Digest Replay
Authentication bypass by capture-replay in Apache Roller 6.1.5 WSSE digest auth lets an attacker who intercepts a valid header gain AtomPub authority. CVSS 7.7 high.
- Vendor
- Apache Software Foundation
- Product
- Apache Roller
- CVSS
- 7.7
- EPSS (exploit probability)
- 0.4%
- Status
- patched
- Published
CVE-2026-82379 is an authentication bypass by capture-replay vulnerability in Apache Roller 6.1.5. The WSSE digest authentication mechanism used for AtomPub does not track nonces, so an attacker who captures a valid WSSE digest authentication header can replay it to gain the victim’s AtomPub publishing authority.
What to do: Upgrade Apache Roller to a patched version. See the NVD record and the Apache Roller GitHub fix.
