Cross-Site Scripting Vulnerability in Apache Roller by Apache
CVE-2026-91206
6.1MEDIUM
What is CVE-2026-91206?
Apache Roller 6.1.5 is susceptible to a Cross-site Scripting (XSS) flaw due to improper input neutralization during web page generation. This vulnerability specifically impacts installations utilizing the optional LDAP comment authenticator, which fails to escape request parameter values when they are rendered in HTML forms. A successful exploit could enable attackers to execute arbitrary scripts in the context of users' sessions who have previously loaded the authenticator form through a crafted link. It is recommended to upgrade to version 6.1.6 or later to ensure that reflected values are properly escaped, mitigating this risk.
Affected Version(s)
Apache Roller 6.1.5