CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-69223

criticalCVSS 9.1covered by 2 sourcesfirst seen 2026-08-11
Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue.

CSIRTS triage

What
Apache Allura contains a server-side request forgery vulnerability that allows attackers to make unauthorized requests from the application server.
Who is affected
All deployments of Apache Allura are affected.
Urgency
Moderate urgency; exploitation status is unconfirmed but SSRF vulnerabilities enable lateral movement and information disclosure in internal networks.
Action
Check the Apache Allura security advisories for patched versions and apply the update immediately.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-69223

Get an email if CVE-2026-69223 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-69223

CVE.org record

Embed the live status

CVE-2026-69223 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-69223 status](https://www.csirts.com/badge/CVE-2026-69223)](https://www.csirts.com/cve/CVE-2026-69223)