CVSS
N/A
CVSS
EPSS
N/A
Exploit Prediction Score
Published
August 12, 2026
Exploitability
No EPSS data available
Insecure Direct Object Reference (IDOR) due to missing permission checks for multiple Artifact types in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue.
No package data available.
Publisher and database URLs for this record (shown for attribution; reading stays in Bugflare).