AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-69223

CRITICAL · CVSS 9.1 EPSS 0.48%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

Apache Allura versions prior to 1.19.1 are vulnerable to Server-Side Request Forgery (SSRF) through their webhooks, potentially allowing attackers to send unauthorized requests from the server. This vulnerability could lead to unauthorized access to internal resources or sensitive data. Organizations using affected versions should prioritize upgrading to 1.19.1 to mitigate this risk.

CVE
CVE-2026-69223
Severity
CRITICAL
CVSS
9.1
EPSS
0.48%
Apache

Original NVD Description

Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue.