PT-2026-99790 · Apache · Apache Roller
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache Roller version 6.1.5
Description
An authenticated user can read, modify, or delete weblog content belonging to other weblogs. This occurs because the handlers for the legacy XML-RPC Blogger and MetaWeblog APIs authenticate the caller but fail to verify if the caller has the necessary permissions for the specific weblog or entry being accessed. This issue only affects installations where the non-default global XML-RPC setting is enabled.
Recommendations
Upgrade to Apache Roller version 6.1.6 or later.
Disable the XML-RPC feature.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Roller