Impact
The vulnerability arises from the OAuth 1.0a authorization endpoint trusting a request-supplied identity rather than the authenticated session. An attacker who has discovered an outstanding request token for a site‑wide consumer can submit an unsigned authorization request that binds the token to any chosen user account, including administrators. The result is unauthorized account takeover and escalation of privileges.
Affected Systems
Apache Roller 6.1.5 and any earlier releases that are configured with an OAuth 1.0a site‑wide consumer. Installations that do not enable this consumer are unaffected.
Risk and Exploitability
The CVSS score of 9 indicates critical severity, and the absence of an EPSS rating does not diminish the inherent risk. The vulnerability is exploitable remotely by an unauthenticated attacker who merely needs to know an active request token, making it a realistic threat for exposed installations. The issue is not listed in CISA’s KEV catalog, but its high severity and ease of exploitation warrant immediate attention.
OpenCVE Enrichment