Improper XML External Entity Handling in Apache Roller 6.1.5 by Apache
CVE-2026-82376
7.7HIGH
What is CVE-2026-82376?
The vulnerability identified in Apache Roller 6.1.5 involves improper handling of XML external entities. This flaw permits users with entry-editing rights to exploit a trackback feature, which can be manipulated to cause the server to process a malicious trackback response. Due to the XML parser's failure to disable external entity resolution, an attacker can gain access to sensitive files readable by the Roller process. Although the Trackback control is not visible in the standard user interface, it remains directly accessible, necessitating no special server configuration. Users are advised to upgrade to Apache Roller 6.1.6 or later to mitigate this issue effectively.
Affected Version(s)
Apache Roller 6.1.5