Cross-Site Scripting Vulnerability in Apache Roller by Apache
CVE-2026-91206

6.1MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
28 September 2026

What is CVE-2026-91206?

Apache Roller 6.1.5 is susceptible to a Cross-site Scripting (XSS) flaw due to improper input neutralization during web page generation. This vulnerability specifically impacts installations utilizing the optional LDAP comment authenticator, which fails to escape request parameter values when they are rendered in HTML forms. A successful exploit could enable attackers to execute arbitrary scripts in the context of users' sessions who have previously loaded the authenticator form through a crafted link. It is recommended to upgrade to version 6.1.6 or later to ensure that reflected values are properly escaped, mitigating this risk.

Affected Version(s)

Apache Roller 6.1.5

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

姬珏 (CyberLeo)
.