Skip to content

Apache Roller: cross-site request forgery

High8.1CVE-2026-82380 · Published Sep 28, 2026

Cross-Site Request Forgery (CSRF) in Apache Roller 6.1.5 allows a remote attacker to cause a logged-in user to perform state-changing actions under the victim's authority, because the CSRF validation filters accept a request that does not submit the required salt token, validating instead against a value the server itself generated for the request. No optional feature or non-default configuration is required; any logged-in author or administrator is affected when induced to visit a crafted page. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which validates only the submitted salt and applies the same check to multipart forms.

Affected versions

PackageAffectedFixed in
Apache Roller
Product
<= 6.1.5No fix yet
Details and references

More Apache Software Foundation advisories

All Apache Software Foundation
Advisory
Apache Karaf: command injection
High8.8Sep 28
LDAPCache and LDAPBackingEngine build LDAP search filters for user lookup and...
High7.3Sep 28
Apache Roller: cross-site scripting
Medium6.1Sep 28
Apache Roller: cross-site scripting
Medium6.1Sep 28
Apache Roller: cross-site scripting
Medium6.1Sep 28
Apache Roller: missing authentication
High8.2Sep 28

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.