AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-73240

CRITICAL · CVSS 9.8 EPSS 0.38%

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

Apache Allura versions prior to 1.19.1 are vulnerable to git argument injection due to improperly handled inputs, potentially allowing an attacker to execute arbitrary commands. This vulnerability poses a significant risk to users who rely on Apache Allura for project management and collaboration. Organizations utilizing this software should prioritize upgrading to version 1.19.1 to mitigate the risk.

CVE
CVE-2026-73240
Severity
CRITICAL
CVSS
9.8
EPSS
0.38%
Apache

Original NVD Description

Specifically crafted inputs may lead to git argument injection in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue.