THREATOPS
THREAT OPSThreat News › CVE-2026-75099: Apache Allura: Unauthenticated REST disclosure

CVE-2026-75099: Apache Allura: Unauthenticated REST disclosure

medoss_secPublished 2026-08-24

<p>Posted by Dave Brondsema on Aug 24</p>Severity: important<br /> <br /> Affected versions:<br /> <br /> - Apache Allura through 1.19.1<br /> <br /> Description:<br /> <br /> Unauthenticated REST disclosure of certain content items in Apache Allura.<br /> <br /> This issue affects Apache Allura: through 1.19.1.<br /> <br /> Users are recommended to upgrade to version 1.20.0, which fixes the issue

Indicators of compromise

Original source: https://seclists.org/oss-sec/2026/q3/560