SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-75099

MEDIUM · CVSS 5.3 EPSS 0.36%

Source: NVD + CISA KEV + EPSS · Published 2026-08-24 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Apache Allura versions up to 1.19.1 are vulnerable to an unauthenticated REST endpoint that can disclose sensitive content items. This could lead to unauthorized access to potentially sensitive information, impacting the confidentiality of the data managed by the application. Organizations using affected versions should prioritize upgrading to version 1.20.0 to mitigate this risk.

CVE
CVE-2026-75099
Severity
MEDIUM
CVSS
5.3
EPSS
0.36%
Apache

Original NVD Description

Unauthenticated REST disclosure of certain content items in Apache Allura. This issue affects Apache Allura: through 1.19.1. Users are recommended to upgrade to version 1.20.0, which fixes the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)