CVE-2026-75099: Apache Allura: Unauthenticated REST disclosure
Published Aug 24, 2026
·Updated
Unauthenticated REST disclosure of certain content items in Apache Allura.
This issue affects Apache Allura: through 1.19.1.
Users are recommended to upgrade to version 1.20.0, which fixes the issue.
Affected Software
1 affected component
Apache Allura<=1.19.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Allurato a version that resolves this vulnerability.Fixed in 1.20.0
Event History
Aug 24, 2026
CVE Published
via MITRE·04:42 PM
Data Sourced
via MITRE·04:42 PM
DescriptionWeakness
Data Sourced
via NVD·05:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which Apache Allura versions are affected?
Apache Allura versions through 1.19.1 are affected. Version 1.20.0 fixes the issue.
2
Does exploiting this issue require authentication or user interaction?
No. The CVSS vector indicates network exploitation with no privileges required and no user interaction.
3
What is the impact of successful exploitation?
The issue can disclose certain content items through REST, resulting in low confidentiality impact. No integrity or availability impact is indicated.