Sceawere

Vulnerability Detail

CVE-2026-82379UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Apache Roller WSSE Replay Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.7
Creation Date
4h ago
Vendor
Apache Software Foundation
Product
Apache Roller
Attack Type
CWE-294: Authentication Bypass by Capture-replay
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
Attack Complexity
HIGH

Narrative and Response

Description

Authentication Bypass by Capture-replay in Apache Roller 6.1.5 allows an attacker who captures a valid WSSE digest authentication header to replay it and gain the victim's AtomPub authority, because the authentication does not enforce nonce uniqueness or timestamp freshness. Only installations that enable the non-default AtomPub API with WSSE authentication and plaintext-compatible password storage are affected. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which removes WSSE as an AtomPub authentication method; existing installations configured for WSSE fail closed until an administrator explicitly selects a supported authentication method.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.7",
  "pubDate": "2026-09-28T08:16:41.663Z",
  "pubdate": "2026-09-28T08:16:41.663Z",
  "executiveSummary": "This vulnerability is an authentication bypass via a capture-replay attack affecting the AtomPub API in Apache Roller 6.1.5.\nThe flaw stems from the implementation of WSSE (Web Services Security Extension) authentication, which fails to enforce critical security controls such as nonce uniqueness and timestamp verification.\nConsequently, an attacker who intercepts a valid WSSE digest authentication header can replay that header to assume the identity and AtomPub authority of the victim.\nThe vulnerability is restricted to installations that explicitly enable the non-default AtomPub API with WSSE authentication alongside plaintext-compatible password storage.\nSuccessful exploitation allows an unauthorized party to bypass authentication mechanisms, resulting in unauthorized access to administrative or user-level AtomPub operations.\nRisk is primarily contained to environments with these specific legacy configurations enabled. Users are advised to upgrade to version 6.1.6 or later, which effectively removes the vulnerable WSSE authentication mechanism to eliminate the attack vector.",
  "technicalDetails": "The root cause of this vulnerability lies in the improper implementation of the WSSE authentication protocol within the Apache Roller 6.1.5 AtomPub API. WSSE is intended to provide secure authentication for web services by using a digest-based mechanism; however, the Apache Roller implementation fails to implement mandatory security primitives required by the specification to prevent replay attacks.\nSpecifically, the system does not enforce nonce uniqueness, nor does it validate the freshness of the request timestamp. In a secure WSSE implementation, the server maintains a cache of used nonces or verifies that the timestamp is within a strictly defined window of the server's current time. By omitting these checks, Apache Roller allows an authentication header to remain valid indefinitely as long as the credentials remain unchanged.\nThe attack flow proceeds as follows: First, an attacker performs network reconnaissance or intercepts traffic (e.g., via man-in-the-middle or packet sniffing) where a legitimate user is communicating with the AtomPub API. The attacker captures the 'X-WSSE' header containing the username, nonce, created timestamp, and the digest (calculated as SHA1(nonce + created + password)). Because the server performs no stateful tracking of the nonce, the attacker can present this identical header in a subsequent request.\nUpon receiving the replayed header, the server-side authentication module recalculates the expected digest using the stored password (facilitated by the requirement for plaintext-compatible password storage). Since the provided nonce and timestamp match the criteria expected by the server—and the server does not check if that specific nonce has already been utilized—the server verifies the request as authentic. The attacker is subsequently granted the same AtomPub authority as the original user.\nThis vulnerability requires that the target environment has the non-default AtomPub API enabled and that the server is configured to utilize WSSE authentication. The reliance on plaintext-compatible password storage is a critical secondary factor, as it allows the server to verify the digest against the stored secret without additional complex hashing overhead. The exploitation occurs over the network, potentially targeting any interface exposing the AtomPub API. Post-exploitation, the attacker gains the ability to manipulate content or perform administrative actions defined within the scope of the hijacked AtomPub authority, effectively resulting in a full session compromise for the targeted user session."
}
CVE-2026-82379: Apache Roller WSSE Replay Vulnerability (HIGH Severity, CVSS: 7.7) | Sceawere