CVE-2026-82378

CVE-2026-82378 published: Incorrect Authorization in the OAuth 1.0a authorization endpoint of Apache Roller 6.1.5 allows an unauthenticated remote attacker who learns an outstanding request token for a configured site-wide consumer to bind that token to an arbitrary user account, in...

View full NVD advisory → ← Back to CVE watch