Authorization Bypass in Apache Roller Affects User Isolation
CVE-2026-82348

7.7HIGH

Key Information:

Vendor

Apache

Vendor
CVE Published:
28 September 2026

What is CVE-2026-82348?

The vulnerability in Apache Roller 6.1.5 allows authenticated users with authoring rights on one weblog to gain unauthorized access to read, modify, or delete resources from another user's weblog. This issue stems from unscoped identifier-based lookups, which pose significant risks in multi-user environments designed for user isolation. An administrator of a weblog can also exploit this flaw to overwrite Velocity templates belonging to other weblogs, compromising the integrity of the impacted resources. To mitigate this vulnerability, users are advised to upgrade to Apache Roller version 6.1.6 or later, which implements scoped authoring resource lookups to ensure proper user isolation.

Affected Version(s)

Apache Roller 6.1.5

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

meifukun
n0mi1k
Ivan Iushkevich (Steph)
.