AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-73239

MEDIUM · CVSS 6.5 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Apache Allura versions prior to 1.19.1 are vulnerable to an Insecure Direct Object Reference (IDOR) due to inadequate permission checks for various Artifact types. This flaw could allow unauthorized access to sensitive resources, potentially leading to data exposure or manipulation. Organizations using affected versions should prioritize upgrading to 1.19.1 to mitigate this security risk.

CVE
CVE-2026-73239
Severity
MEDIUM
CVSS
6.5
EPSS
0.23%
Apache

Original NVD Description

Insecure Direct Object Reference (IDOR) due to missing permission checks for multiple Artifact types in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue.