Skip to content
feed: live
>_0dayNews
CVE Record
[ HIGH ]CVE-2026-82379

Apache Roller WSSE Auth Bypass via Digest Replay

Authentication bypass by capture-replay in Apache Roller 6.1.5 WSSE digest auth lets an attacker who intercepts a valid header gain AtomPub authority. CVSS 7.7 high.

cat cve-2026-82379.json
Vendor
Apache Software Foundation
Product
Apache Roller
CVSS
7.7
EPSS (exploit probability)
0.4%
Status
patched
Published

CVE-2026-82379 is an authentication bypass by capture-replay vulnerability in Apache Roller 6.1.5. The WSSE digest authentication mechanism used for AtomPub does not track nonces, so an attacker who captures a valid WSSE digest authentication header can replay it to gain the victim’s AtomPub publishing authority.

What to do: Upgrade Apache Roller to a patched version. See the NVD record and the Apache Roller GitHub fix.