Junglewise Threat Intelligence

CVE-2026-75099: Apache Allura unauthenticated REST disclosure of content items

CVE-2026-75099 · Severity: medium · CVSS 5.3 · Published 2026-08-24

Technologies: Apache Allura. Vendors: Apache.

Executive brief

Apache Allura is an open-source project management and collaboration platform. An unauthenticated attacker can access certain sensitive content items through the REST API that should have been restricted, potentially exposing private project data, documents, or communications to unauthorized users.

Technical details

The vulnerability is an information disclosure flaw in Apache Allura's REST API that allows unauthenticated access to certain content items that should require authentication. The root cause is improper access control checks on REST API endpoints. An attacker with network access to the Allura instance can directly query the REST API without authentication to retrieve sensitive content. This impacts confidentiality of restricted project data. The issue affects versions through 1.19.1 and has been fixed in version 1.20.0.

Affected products

  • Apache Allura through 1.19.1

Timeline

  • 2026-08-24: disclosed
  • 2026: patched: Fix available in version 1.20.0

References

Related threats