CVE-2026-82379 Details
Description
Authentication Bypass by Capture-replay in Apache Roller 6.1.5 allows an attacker who captures a valid WSSE digest authentication header to replay it and gain the victim's AtomPub authority, because the authentication does not enforce nonce uniqueness or timestamp freshness. Only installations that enable the non-default AtomPub API with WSSE authentication and plaintext-compatible password storage are affected. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which removes WSSE as an AtomPub authentication method; existing installations configured for WSSE fail closed until an administrator explicitly selects a supported authentication method.
An authentication bypass vulnerability allowing capture-replay attacks has been identified in Apache Roller version 6.1.5. This issue arises because the WSSE digest authentication method used by the AtomPub API does not require unique nonces or fresh timestamps, enabling an attacker to replay a valid authentication header and gain unauthorized access to the victim's AtomPub authority. The vulnerability affects only installations that have activated the AtomPub API with WSSE authentication and use plaintext-compatible password storage.
Users are advised to upgrade to Apache Roller version 6.1.6 or later, which removes WSSE authentication from the AtomPub API. For installations already using WSSE, the application will fail closed until an administrator selects a supported authentication method.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 28, 2026CISA-ADP
Assessed Sep 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/09/25/12 | CVE | AdvisoryMailing ListRemedy |
| https://github.com/apache/roller/pull/166 | [email protected] | Issue TrackingVendor |
| https://lists.apache.org/thread/bg5r225c3z4148z6kf7s3fwwgrs2lx02 | [email protected] | AdvisoryMailing ListRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-294 | Authentication Bypass by Capture-replay | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Apache Roller | 6.1.5 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 29, 2026 | CVE Modified | CISA-ADP |
| Sep 29, 2026 | CVE Modified | CISA-ADP |
| Sep 28, 2026 | CVE Modified | CVE |
| Sep 28, 2026 | New CVE Received | [email protected] |
Volerion