Cross-Site Request Forgery Vulnerability in Apache Roller by Apache
CVE-2026-82380

8.1HIGH

Key Information:

Vendor

Apache

Vendor
CVE Published:
28 September 2026

What is CVE-2026-82380?

A vulnerability in Apache Roller 6.1.5 allows attackers to exploit Cross-Site Request Forgery (CSRF) weaknesses. This issue enables a remote attacker to manipulate an authenticated user's actions without their consent, as the CSRF filtering mechanism inadequately verifies the required salt token, instead accepting a value created by the server. This vulnerability impacts authors and administrators who are tricked into visiting malicious websites. To mitigate this risk, users must upgrade to Apache Roller 6.1.6 or later, which strengthens salt validation and applies necessary checks to multipart forms.

Affected Version(s)

Apache Roller 6.1.5

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

meifukun
.