Missing Authorization in Apache Roller Affects User Weblog Content Management
CVE-2026-82377

9.9CRITICAL

Key Information:

Vendor

Apache

Vendor
CVE Published:
28 September 2026

What is CVE-2026-82377?

Apache Roller version 6.1.5 is susceptible to a missing authorization vulnerability that permits authenticated users to access, modify, or delete weblog content across different weblogs. This issue arises due to the legacy XML-RPC Blogger and MetaWeblog APIs, where the handlers correctly authenticate the caller but fail to verify the caller's permissions on the target weblog or entry. The vulnerability only impacts installations that enable the non-default global XML-RPC setting. Users are urged to upgrade to Apache Roller version 6.1.6 or higher, which implements a per-method permission check, or to disable the XML-RPC feature to mitigate potential risks.

Affected Version(s)

Apache Roller 6.1.5

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

meifukun
n0mi1k
Ivan Iushkevich (Steph)
.