Description
Incorrect Authorization in the OAuth 1.0a authorization endpoint of Apache Roller 6.1.5 allows an unauthenticated remote attacker who learns an outstanding request token for a configured site-wide consumer to bind that token to an arbitrary user account, including an administrator, by submitting an unsigned authorization request. The endpoint derives the authorizing identity from a request-supplied value rather than the authenticated session. Only installations that configure an OAuth 1.0a site-wide consumer are affected, and exploitation requires knowledge of one of its outstanding request tokens. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which binds authorization to the logged-in session.
Published: 2026-09-28
Score: 9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation to arbitrary accounts
Action: Patch
AI Analysis

Impact

The vulnerability arises from the OAuth 1.0a authorization endpoint trusting a request-supplied identity rather than the authenticated session. An attacker who has discovered an outstanding request token for a site‑wide consumer can submit an unsigned authorization request that binds the token to any chosen user account, including administrators. The result is unauthorized account takeover and escalation of privileges.

Affected Systems

Apache Roller 6.1.5 and any earlier releases that are configured with an OAuth 1.0a site‑wide consumer. Installations that do not enable this consumer are unaffected.

Risk and Exploitability

The CVSS score of 9 indicates critical severity, and the absence of an EPSS rating does not diminish the inherent risk. The vulnerability is exploitable remotely by an unauthenticated attacker who merely needs to know an active request token, making it a realistic threat for exposed installations. The issue is not listed in CISA’s KEV catalog, but its high severity and ease of exploitation warrant immediate attention.

Generated by OpenCVE AI on September 28, 2026 at 09:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Roller to version 6.1.6 or later, which binds authorization to the logged‑in session and removes the flaw.
  • If an upgrade is not feasible, disable or remove the OAuth 1.0a site‑wide consumer configuration to eliminate the attack surface.
  • Restrict external access to the OAuth authorization endpoint, for example by firewall or reverse‑proxy rules, to mitigate the risk while no patch is applied.

Generated by OpenCVE AI on September 28, 2026 at 09:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache roller
Vendors & Products Apache
Apache roller

Mon, 28 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
References

Mon, 28 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description Incorrect Authorization in the OAuth 1.0a authorization endpoint of Apache Roller 6.1.5 allows an unauthenticated remote attacker who learns an outstanding request token for a configured site-wide consumer to bind that token to an arbitrary user account, including an administrator, by submitting an unsigned authorization request. The endpoint derives the authorizing identity from a request-supplied value rather than the authenticated session. Only installations that configure an OAuth 1.0a site-wide consumer are affected, and exploitation requires knowledge of one of its outstanding request tokens. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which binds authorization to the logged-in session.
Title Apache Roller: OAuth authorization endpoint trusts request-supplied identity
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-28T08:21:29.048Z

Reserved: 2026-08-28T20:43:12.556Z

Link: CVE-2026-82378

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-28T08:16:41.540

Modified: 2026-09-28T14:29:44.860

Link: CVE-2026-82378

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T10:00:11Z

Weaknesses