CVE WATCH / VULNERABILITY DETAIL

CVE-2026-82379

HIGHCVSS 7.7NVD feed

Published 28 September 2026 · tracked since 28 September 2026

Description

Authentication Bypass by Capture-replay in Apache Roller 6.1.5 allows an attacker who captures a valid WSSE digest authentication header to replay it and gain the victim's AtomPub authority, because the authentication does not enforce nonce uniqueness or timestamp freshness. Only installations that

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-82379 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-82379

HIGHCVSS 7.7NVD feed

Published 28 September 2026 · tracked since 28 September 2026

Description

Authentication Bypass by Capture-replay in Apache Roller 6.1.5 allows an attacker who captures a valid WSSE digest authentication header to replay it and gain the victim's AtomPub authority, because the authentication does not enforce nonce uniqueness or timestamp freshness. Only installations that

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]