PT-2026-99788 · Apache · Apache Roller

·

CVE-2026-82348

·

Published

2026-09-28

·

Updated

2026-09-28

CVSS v3.1

7.7

High

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions Apache Roller version 6.1.5
Description An authorization bypass exists that allows an authenticated user with authoring rights on one weblog to read, modify, or delete resources belonging to another weblog. This occurs through unscoped identifier-based lookups in multi-user installations where users should be isolated. Additionally, a user with administrator rights on their own weblog can overwrite the Velocity template of another weblog, which is then evaluated when the victim weblog renders. Velocity is a Java-based template engine used to generate dynamic content.
Recommendations Upgrade Apache Roller to version 6.1.6 or later.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82348

Affected Products

Apache Roller