CVE-2026-73239
MEDIUM NVDCVSS Score
6.5
Severity
MEDIUM
Source
NVD
Published
Aug 12, 2026
Description
Insecure Direct Object Reference (IDOR) due to missing permission checks for multiple Artifact types in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue.