PT-2026-99790 · Apache · Apache Roller

·

CVE-2026-82377

·

Published

2026-09-28

·

Updated

2026-09-29

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Roller version 6.1.5
Description An authenticated user can read, modify, or delete weblog content belonging to other weblogs. This occurs because the handlers for the legacy XML-RPC Blogger and MetaWeblog APIs authenticate the caller but fail to verify if the caller has the necessary permissions for the specific weblog or entry being accessed. This issue only affects installations where the non-default global XML-RPC setting is enabled.
Recommendations Upgrade to Apache Roller version 6.1.6 or later. Disable the XML-RPC feature.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82377

Affected Products

Apache Roller