Medium severity5.3NVD Advisory· Published Aug 24, 2026· Updated Aug 28, 2026
CVE-2026-75099
CVE-2026-75099
Description
Unauthenticated REST disclosure of certain content items in Apache Allura.
This issue affects Apache Allura: through 1.19.1.
Users are recommended to upgrade to version 1.20.0, which fixes the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
2- www.openwall.com/lists/oss-security/2026/08/24/6nvdMailing ListThird Party Advisory
- lists.apache.org/thread/lnsfx58o6mx6m44qk4vzqrq8ccmrywcynvdMailing ListVendor Advisory
News mentions
2- Apache: 25 Vulnerabilities Across Tomcat, Camel, Hive, and More Disclosed Aug 24-26Vypr Intelligence · Aug 26, 2026
- Apache: Batch of 11 CVEs Hits Camel, Allura, and More on August 23-24, 2026Vypr Intelligence · Aug 24, 2026