Authorization Bypass in Apache Roller Affects User Isolation
CVE-2026-82348
7.7HIGH
What is CVE-2026-82348?
The vulnerability in Apache Roller 6.1.5 allows authenticated users with authoring rights on one weblog to gain unauthorized access to read, modify, or delete resources from another user's weblog. This issue stems from unscoped identifier-based lookups, which pose significant risks in multi-user environments designed for user isolation. An administrator of a weblog can also exploit this flaw to overwrite Velocity templates belonging to other weblogs, compromising the integrity of the impacted resources. To mitigate this vulnerability, users are advised to upgrade to Apache Roller version 6.1.6 or later, which implements scoped authoring resource lookups to ensure proper user isolation.
Affected Version(s)
Apache Roller 6.1.5