Description
Authentication Bypass by Capture-replay in Apache Roller 6.1.5 allows an attacker who captures a valid WSSE digest authentication header to replay it and gain the victim's AtomPub authority, because the authentication does not enforce nonce uniqueness or timestamp freshness. Only installations that enable the non-default AtomPub API with WSSE authentication and plaintext-compatible password storage are affected. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which removes WSSE as an AtomPub authentication method; existing installations configured for WSSE fail closed until an administrator explicitly selects a supported authentication method.
Published: 2026-09-28
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Authentication bypass via replay of WSSE headers
Action: Upgrade
AI Analysis

Impact

The flaw allows an attacker who captures a valid WSSE digest authentication header to reuse it and gain access to the victim's AtomPub resources. Because the implementation does not enforce nonce uniqueness or timestamp freshness, a replayed header is treated as fresh and accepted, providing a direct authentication bypass.

Affected Systems

The issue affects Apache Roller installations that use the AtomPub API with WSSE authentication enabled and rely on plaintext‑compatible password storage. Specifically, Apache Roller 6.1.5 and earlier are vulnerable where the non‑default AtomPub service is configured to use WSSE.

Risk and Exploitability

The CVSS score of 7.7 indicates a high severity vulnerability with a high impact if exploited. There is no EPSS score available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves network capture of the AtomPub traffic; upon intercepting a WSSE header, an attacker can replay it without modification. The vulnerability remains exploitable until WSSE is disabled or Railsimin upgraded to a version that removes WSSE as an AtomPub authentication method.

Generated by OpenCVE AI on September 28, 2026 at 09:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Roller to version 6.1.6 or later, where WSSE is removed from the AtomPub authentication methods.
  • If an upgrade is not immediately possible, disable WSSE authentication for the AtomPub API and configure a supported method such as Basic or OAuth.
  • Ensure that password storage is not plaintext‑compatible; enforce secure hashing or encryption for stored passwords.
  • Apply HTTPS to the AtomPub endpoint to prevent network capture of authentication headers.

Generated by OpenCVE AI on September 28, 2026 at 09:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache roller
Vendors & Products Apache
Apache roller

Mon, 28 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
References

Mon, 28 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Description Authentication Bypass by Capture-replay in Apache Roller 6.1.5 allows an attacker who captures a valid WSSE digest authentication header to replay it and gain the victim's AtomPub authority, because the authentication does not enforce nonce uniqueness or timestamp freshness. Only installations that enable the non-default AtomPub API with WSSE authentication and plaintext-compatible password storage are affected. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which removes WSSE as an AtomPub authentication method; existing installations configured for WSSE fail closed until an administrator explicitly selects a supported authentication method.
Title Apache Roller: WSSE digest authentication headers can be replayed
Weaknesses CWE-294
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-28T08:21:31.678Z

Reserved: 2026-08-28T20:44:04.602Z

Link: CVE-2026-82379

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T08:16:41.663

Modified: 2026-09-28T09:17:06.167

Link: CVE-2026-82379

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T10:00:11Z

Weaknesses
  • CWE-294

    Authentication Bypass by Capture-replay