Missing Authorization in Apache Roller Affects User Weblog Content Management
CVE-2026-82377
9.9CRITICAL
What is CVE-2026-82377?
Apache Roller version 6.1.5 is susceptible to a missing authorization vulnerability that permits authenticated users to access, modify, or delete weblog content across different weblogs. This issue arises due to the legacy XML-RPC Blogger and MetaWeblog APIs, where the handlers correctly authenticate the caller but fail to verify the caller's permissions on the target weblog or entry. The vulnerability only impacts installations that enable the non-default global XML-RPC setting. Users are urged to upgrade to Apache Roller version 6.1.6 or higher, which implements a per-method permission check, or to disable the XML-RPC feature to mitigate potential risks.
Affected Version(s)
Apache Roller 6.1.5