Junglewise Threat Intelligence

CVE-2026-81270: Apache Allura exposure of non-public information via search

CVE-2026-81270 · Severity: high · CVSS 7.5 · Published 2026-09-04

Technologies: Apache Allura. Vendors: Apache.

Executive brief

Apache Allura is a web-based project management and collaboration platform. This vulnerability allows attackers to expose non-public information through the search functionality, potentially revealing sensitive project data that should be restricted. An attacker can leverage this to bypass access controls and view confidential information.

Technical details

The vulnerability is an information exposure issue in Apache Allura's search functionality that allows unauthorized access to non-public information. The affected versions through 1.20.0 fail to properly enforce access controls during search queries, enabling attackers to retrieve restricted data. The attack requires network access to the search feature but does not require authentication or user interaction. Attackers can query the search interface to disclose confidential project information. The issue is resolved in version 1.21.0.

Affected products

  • Apache Allura through 1.20.0

Timeline

  • 2026-09-04: disclosed
  • 2026-09-04: patched: Fixed in version 1.21.0

References

Related threats