CVE-2026-69223: Apache Allura: Server-side request forgery
Published Aug 11, 2026
·Updated
Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF).
This issue affects Apache Allura: before 1.19.1.
Users are recommended to upgrade to version 1.19.1, which fixes the issue.
Affected Software
1 affected component
Apache Allura<1.19.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Allurato a version that resolves this vulnerability.Fixed in 1.19.1
Event History
Aug 11, 2026
CVE Published
via MITRE·05:03 PM
Data Sourced
via MITRE·05:03 PM
DescriptionWeakness
Data Sourced
via NVD·05:19 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-69223?
The severity of CVE-2026-69223 is rated at 56.
2
How do I fix CVE-2026-69223?
To fix CVE-2026-69223, upgrade Apache Allura to version 1.19.1 or later.
3
What type of vulnerability is CVE-2026-69223?
CVE-2026-69223 is a Server-Side Request Forgery (SSRF) vulnerability.
4
Which versions of Apache Allura are affected by CVE-2026-69223?
CVE-2026-69223 affects all versions of Apache Allura prior to 1.19.1.
5
What are the potential impacts of CVE-2026-69223?
CVE-2026-69223 could allow an attacker to exploit the SSRF vulnerability to make unauthorized requests from the server.