Apache Roller: 18 Vulnerabilities Including Critical Flaws Disclosed Together
Key findings • 18 vulnerabilities disclosed for Apache Roller 6.1.5 on September 28, 2026. • Critical vulnerabilities include deserialization, configuration bypass, and authorization flaws. …

Key findings
- 18 vulnerabilities disclosed for Apache Roller 6.1.5 on September 28, 2026.
- Critical vulnerabilities include deserialization, configuration bypass, and authorization flaws.
- Multiple XSS, XXE, and SSRF vulnerabilities impact data integrity and server access.
- Authentication bypass and CSRF flaws allow unauthorized actions and session hijacking.
- All disclosed issues affect version 6.1.5, necessitating urgent updates.
On September 28, 2026, a batch of 18 vulnerabilities was disclosed for Apache Roller, a popular Java-based weblogging platform. These vulnerabilities, all discovered and reported on the same day, range in severity from medium to critical, with several allowing for unauthenticated remote attackers to gain significant control over affected installations. The disclosures highlight a range of security weaknesses including cross-site scripting (XSS), XML external entity (XXE) injection, deserialization flaws, and authorization bypasses.
Several vulnerabilities stem from improper handling of user input, leading to cross-site scripting (XSS) attacks. CVE-2026-91206 and CVE-2026-82546 allow attackers to inject scripts through crafted comments or trackback requests, potentially affecting moderators or visitors. CVE-2026-91204 enables script execution via crafted comments containing javascript: URIs, while CVE-2026-82381 allows stored script execution within the authoring UI. CVE-2026-82382 presents a reflected XSS against visitors using the frontpage theme via a crafted blog-directory parameter. Additionally, CVE-2026-86507 allows anonymous remote attackers to store a crafted comment-author URL that can execute script in the session of a weblog moderator or global administrator. CVE-2026-82387 permits users with media-upload rights to store active content by exploiting the media upload feature's trust in the upload-supplied content type.
A significant number of the disclosed vulnerabilities involve authorization and access control issues. CVE-2026-82384, a critical deserialization flaw, allows unauthenticated remote attackers to execute arbitrary code by exploiting vendor extension types in the XML-RPC endpoint. CVE-2026-82383, another critical vulnerability, allows unauthenticated attackers to persistently change site-global configuration values, such as the frontpage weblog selection, due to an anonymously reachable setup action. CVE-2026-82378, a critical OAuth 1.0a authorization bypass, enables an unauthenticated attacker to bind a request token to an arbitrary user account. CVE-2026-82377, a critical missing authorization vulnerability, allows authenticated users to manipulate content across different weblogs via legacy XML-RPC APIs. CVE-2026-82348, a high-severity authorization bypass, allows authenticated users to access resources belonging to other weblogs through unscoped identifier-based lookups.
Further impacting security are vulnerabilities related to XML external entity (XXE) processing and sensitive information exposure. CVE-2026-82386 and CVE-2026-82376, both high-severity XXE flaws, allow administrators or users with editing rights to read files on the server or internal network addresses by importing crafted OPML or trackback responses, respectively, due to the XML parser not disabling external entity resolution. CVE-2026-82385, a medium-severity vulnerability, allows administrators to read files on the application classpath, including configuration files with secrets, by authoring a Velocity template with an include directive.
The batch also includes a high-severity Cross-Site Request Forgery (CSRF) vulnerability, CVE-2026-82380, which allows attackers to trick logged-in users into performing state-changing actions. Additionally, CVE-2026-82379, a high-severity authentication bypass, permits attackers to replay captured WSSE digest authentication headers to gain a victim's AtomPub authority. Finally, CVE-2026-82375, a high-severity Server-Side Request Forgery (SSRF) vulnerability, allows authenticated users to initiate outbound HTTP requests to attacker-chosen destinations through legacy trackback and entry enclosure handling.
All disclosed vulnerabilities affect Apache Roller version 6.1.5. Users are strongly advised to update to a patched version as soon as possible. The clustered disclosure of these numerous and severe vulnerabilities underscores the importance of timely patching and security audits for all Apache Roller installations.
Key Findings:
- 18 vulnerabilities disclosed for Apache Roller 6.1.5 on September 28, 2026.
- Critical vulnerabilities include deserialization, configuration bypass, and authorization flaws.
- Multiple XSS, XXE, and SSRF vulnerabilities impact data integrity and server access.
- Authentication bypass and CSRF flaws allow unauthorized actions and session hijacking.
- All disclosed issues affect version 6.1.5, necessitating urgent updates.
- A range of security weaknesses were addressed in a single disclosure event.