Sceawere

Vulnerability Detail

CVE-2026-82378UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Apache Roller OAuth Authorization Bypass

Vulnerability Metadata

Severity
Critical
Score / CVSS
9
Creation Date
4h ago
Vendor
Apache Software Foundation
Product
Apache Roller
Attack Type
CWE-863: Incorrect Authorization
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

Incorrect Authorization in the OAuth 1.0a authorization endpoint of Apache Roller 6.1.5 allows an unauthenticated remote attacker who learns an outstanding request token for a configured site-wide consumer to bind that token to an arbitrary user account, including an administrator, by submitting an unsigned authorization request. The endpoint derives the authorizing identity from a request-supplied value rather than the authenticated session. Only installations that configure an OAuth 1.0a site-wide consumer are affected, and exploitation requires knowledge of one of its outstanding request tokens. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which binds authorization to the logged-in session.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.0",
  "pubDate": "2026-09-28T08:16:41.540Z",
  "pubdate": "2026-09-28T08:16:41.540Z",
  "executiveSummary": "This vulnerability is an Incorrect Authorization flaw within the OAuth 1.0a authorization endpoint of Apache Roller 6.1.5, representing a critical security configuration issue.\nThe vulnerability allows an unauthenticated remote attacker to perform an account takeover or unauthorized binding by manipulating the authorization request flow.\nThe core impact is the ability for an attacker to link a known, outstanding request token to any arbitrary user account, including administrative accounts, bypassing intended security controls.\nAffected systems are limited to installations of Apache Roller 6.1.5 that have configured an OAuth 1.0a site-wide consumer.\nExploitation requires the attacker to possess knowledge of an outstanding request token previously generated for the configured site-wide consumer.\nThis flaw results in a complete compromise of the authorization integrity for the targeted user account, granting the attacker the associated privileges of that account.",
  "technicalDetails": "The root cause of this vulnerability lies in the improper implementation of identity verification within the OAuth 1.0a authorization endpoint of Apache Roller 6.1.5. Specifically, the application fails to utilize the authenticated session of the end-user to determine the authorizing identity. Instead, the endpoint incorrectly relies on a request-supplied parameter to identify which user is granting authorization to the OAuth request token.\nIn a secure OAuth 1.0a flow, the authorization step must implicitly bind the request token to the currently authenticated session user on the service provider side. By decoupling this process from the active session and trusting client-provided input, the endpoint introduces a mechanism where the server-side authorization state can be manipulated by an external entity.\nThe exploitation flow proceeds as follows: First, an attacker must acquire a valid, outstanding request token that has been generated for a site-wide OAuth 1.0a consumer. Second, the attacker constructs an unsigned authorization request to the vulnerable endpoint. Third, the attacker injects an arbitrary identity identifier into the request parameters, representing the target user they wish to impersonate or bind. Fourth, the application processes this request and, due to the lack of session-based validation, incorrectly associates the attacker-controlled request token with the account specified in the manipulated request parameter.\nBecause the application does not mandate cryptographic signatures or session-based verification for this specific authorization step, the attacker can successfully bind the token to an administrator account without needing the administrator's credentials. Once the token is successfully bound to the victim's account, the attacker can proceed with the standard OAuth dance to exchange the authorized request token for an access token, granting them persistent, authorized access to the victim's account.\nThis vulnerability persists because the endpoint design treats the authorization identity as mutable input rather than a server-side verified attribute tied to the active user session. This leads to a total compromise of the authorization boundary, allowing attackers to escalate privileges to the highest level available within the application environment if an administrator's account is targeted.\nThe vulnerability is specific to version 6.1.5 and necessitates that the application is explicitly configured for site-wide OAuth 1.0a, which limits the attack surface to specifically hardened or configured instances of the platform."
}
CVE-2026-82378: Apache Roller OAuth Authorization Bypass (CRITICAL Severity, CVSS: 9.0) | Sceawere