Apache · Apache Roller · CVE-2026-82348
**Name of the Vulnerable Software and Affected Versions**
Apache Roller version 6.1.5
**Description**
An authorization bypass exists that allows an authenticated user with authoring rights on one weblog to read, modify, or delete resources belonging to another weblog. This occurs through unscoped identifier-based lookups in multi-user installations where users should be isolated. Additionally, a user with administrator rights on their own weblog can overwrite the Velocity template of another weblog, which is then evaluated when the victim weblog renders. Velocity is a Java-based template engine used to generate dynamic content.
**Recommendations**
Upgrade Apache Roller to version 6.1.6 or later.