SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-73240

CRITICAL · CVSS 9.8 EPSS 0.54%

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-09-11

CyberRota Analysis

AI-Generated

Apache Allura versions prior to 1.19.1 are vulnerable to git argument injection due to improperly handled inputs, potentially allowing an attacker to execute arbitrary commands. This vulnerability poses a significant risk to users who rely on Apache Allura for project management and collaboration. Organizations utilizing this software should prioritize upgrading to version 1.19.1 to mitigate the risk.

CVE
CVE-2026-73240
Severity
CRITICAL
CVSS
9.8
EPSS
0.54%
Apache

Original NVD Description

Specifically crafted inputs may lead to git argument injection in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)