SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-81270

HIGH · CVSS 7.5 EPSS 0.39%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Apache Allura versions up to 1.20.0 are vulnerable to unauthorized exposure of non-public information through search functionality. This could lead to sensitive data being inadvertently disclosed to unauthorized users. Organizations using affected versions should prioritize upgrading to version 1.21.0 to mitigate this risk.

CVE
CVE-2026-81270
Severity
HIGH
CVSS
7.5
EPSS
0.39%
Apache

Original NVD Description

Apache Allura: exposure of non-public information via search. This issue affects Apache Allura: through 1.20.0. Users are recommended to upgrade to version 1.21.0, which fixes the issue.