https://seclists.org/oss-sec/2026/q3/560: CVE-2026-75099: Apache Allura: Unauthenticated ST disclosu
Published Aug 24, 2026
·Updated
Affected Software
1 affected component
Apache Allura<=1.19.1
Frequently Asked Questions
1
Which Apache Allura installations are affected?
Apache Allura versions through 1.19.1 are affected. Version 1.20.0 fixes the issue.
2
What access does an attacker need to exploit this issue?
The disclosure is reachable through the REST interface without authentication, so an attacker does not need to log in.
3
What is the recommended remediation?
Upgrade Apache Allura to version 1.20.0.