Apache Roller: insecure direct object reference
High7.7CVE-2026-82348 · Published Sep 28, 2026 · updated Sep 29, 2026
Authorization Bypass Through User-Controlled Key in Apache Roller 6.1.5 allows an authenticated user with authoring rights on one weblog to read, modify, or delete resources belonging to another weblog through unscoped identifier-based lookups. This affects multi-user installations where users are intended to be isolated between weblogs; no optional feature or non-default configuration is required. A user with administrator rights on their weblog can also overwrite another weblog's Velocity template, whose content is evaluated when the victim weblog renders. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which scopes authoring resource lookups to the acting weblog.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Apache Roller Product | <= 6.1.5 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:L
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-639
More Apache Software Foundation advisories
All Apache Software Foundation| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 28 | Apache Karaf: command injection | High8.8 | 4.4.12 |
| Sep 28 | LDAPCache and LDAPBackingEngine build LDAP search filters for user lookup and... | High7.3 | 4.4.12 |
| Sep 28 | Apache Roller: cross-site scripting | Medium6.1 | No fix yet |
| Sep 28 | Apache Roller: cross-site scripting | Medium6.1 | No fix yet |
| Sep 28 | Apache Roller: cross-site scripting | Medium6.1 | No fix yet |
| Sep 28 | Apache Roller: missing authentication | High8.2 | No fix yet |