Authentication Bypass by Capture-replay in Apache Roller 6.1.5 allows an attacker who captures a valid WSSE digest authentication header to replay it and gain the victim's AtomPub authority, because the authentication does not enforce nonce uniqueness or timestamp freshness. Only installations that enable the non-default AtomPub API with WSSE authentication and plaintext-compatible password storage are affected. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which removes WSSE as an AtomPub authentication method; existing installations configured for WSSE fail closed until an administrator explicitly selects a supported authentication method.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-82379 represents a critical authentication bypass vulnerability in Apache Roller 6.1.5 affecting the AtomPub API when configured with WSSE (Web Services Security) digest authentication. The vulnerability exists because the authentication mechanism fails to enforce nonce uniqueness or validate timestamp freshness, allowing attackers who intercept valid WSSE digest headers to replay them indefinitely and impersonate authenticated users. While the vulnerability only impacts non-default AtomPub configurations with WSSE enabled and plaintext-compatible password storage, organizations using these settings face complete compromise of AtomPub API authority. This is a high-severity issue (CVSS 7.7) that enables unauthorized access to content publishing and management capabilities without active CISA KEV exploitation to date.
Although no direct MITRE ATT&CK technique mappings were provided for this CVE, Casky.ai's security skills would detect attack patterns consistent with T1110 (Brute Force) and T1187 (Forced Authentication) by monitoring for suspicious authentication header reuse and replay patterns. Practitioners using Casky would observe findings flagged around: repeated identical WSSE digest authentication headers appearing across different timestamps and sessions, authentication requests originating from unexpected network locations using captured credentials, and abnormal API access patterns following potential credential capture events. The platform's extended reasoning capabilities would correlate these behavioral anomalies to identify replay-based attacks before they result in unauthorized AtomPub modifications, enabling teams to detect and respond to compromise attempts targeting their authentication infrastructure.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-82379. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation