Improper XML Entity Reference in Apache Roller Weblog
CVE-2026-82386
7.7HIGH
What is CVE-2026-82386?
A vulnerability in Apache Roller version 6.1.5 stems from improper handling of XML external entities. This flaw allows a weblog administrator to read sensitive files and access internal network addresses by importing a specially crafted OPML document. The vulnerability arises because the bookmark import parser fails to disable external entity resolution, enabling attackers to exploit this weakness without requiring any non-default configuration. Administrators are strongly advised to upgrade to Apache Roller version 6.1.6 or later, which implements a hardened parser that disables external entities and document type declarations for enhanced security.
Affected Version(s)
Apache Roller 6.1.5