Unauth REST Disclosure in Apache Allura <=1.19.1
CVE-2026-75099 Published on August 24, 2026
Apache Allura: Unauthenticated REST disclosure
Unauthenticated REST disclosure of certain content items in Apache Allura.
This issue affects Apache Allura: through 1.19.1.
Users are recommended to upgrade to version 1.20.0, which fixes the issue.
Vulnerability Analysis
CVE-2026-75099 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality, a small impact on integrity and availability.
Weakness Type
What is an Information Disclosure Vulnerability?
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVE-2026-75099 has been classified to as an Information Disclosure vulnerability or weakness.
Products Associated with CVE-2026-75099
Want to know whenever a new CVE is published for Apache Allura? stack.watch will email you.
Affected Versions
Apache Software Foundation Apache Allura:- Before and including 1.19.1 is affected.