Skip to content

Apache Roller: missing authorization

Critical9.9CVE-2026-82377 · Published Sep 28, 2026 · updated Sep 29, 2026

Missing Authorization in Apache Roller 6.1.5 allows an authenticated user to read, modify, or delete weblog content belonging to other weblogs through the legacy XML-RPC Blogger and MetaWeblog APIs, because the handlers authenticate the caller but do not verify the caller's permission on the weblog or entry actually affected. Only installations that enable the non-default global XML-RPC setting are affected; the per-weblog API flag defaults to enabled for UI-created weblogs. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which applies an explicit per-method permission check, or to keep the XML-RPC feature disabled.

Affected versions

PackageAffectedFixed in
Apache Roller
Product
<= 6.1.5No fix yet
Details and references

More Apache Software Foundation advisories

All Apache Software Foundation
Advisory
Apache Karaf: command injection
High8.8Sep 28
LDAPCache and LDAPBackingEngine build LDAP search filters for user lookup and...
High7.3Sep 28
Apache Roller: cross-site scripting
Medium6.1Sep 28
Apache Roller: cross-site scripting
Medium6.1Sep 28
Apache Roller: cross-site scripting
Medium6.1Sep 28
Apache Roller: missing authentication
High8.2Sep 28

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.