Improper XML External Entity Handling in Apache Roller 6.1.5 by Apache
CVE-2026-82376

7.7HIGH

Key Information:

Vendor

Apache

Vendor
CVE Published:
28 September 2026

What is CVE-2026-82376?

The vulnerability identified in Apache Roller 6.1.5 involves improper handling of XML external entities. This flaw permits users with entry-editing rights to exploit a trackback feature, which can be manipulated to cause the server to process a malicious trackback response. Due to the XML parser's failure to disable external entity resolution, an attacker can gain access to sensitive files readable by the Roller process. Although the Trackback control is not visible in the standard user interface, it remains directly accessible, necessitating no special server configuration. Users are advised to upgrade to Apache Roller 6.1.6 or later to mitigate this issue effectively.

Affected Version(s)

Apache Roller 6.1.5

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

meifukun
.