Skip to content
Rota Nacional

Cyber ·

Apache Roller: WSSE header can be replayed

A September 25, 2026 security notice says a captured valid WSSE digest header can be replayed to gain the victim’s AtomPub authority in Apache Roller 6.1.5.

A security post attributed to David M. Johnson in the oss-sec feed on September 25, 2026 describes CVE-2026-82379 in Apache Roller 6.1.5. According to the text, an attacker who captures a valid WSSE digest authentication header can reuse it to gain the victim’s AtomPub authority. The issue is attributed to authentication not requiring a unique nonce or a current timestamp. The notice calls the severity moderate, while reporting a CVSS 3.1 score of 7.7, identified as high. The available excerpt does not detail other affected versions or remediation steps.

To confirm the scope and track any fixes, consult the original oss-sec post and compare its details with official Apache Roller advisories and CVE records. If using AI to study the notice or prepare an analysis, do not enter credentials, personal data, or internal installation details; share only what is necessary under your organization’s policy.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free