CVE-2026-82348: Apache Roller: Cross-weblog resource tampering via unscoped authoring lookups
Apache Roller 6.1.5 lets one weblog's authors tamper with another weblog's resources.
Apache disclosed CVE-2026-82348 in Apache Roller 6.1.5. An authorization bypass through a user-controlled key lets an authenticated user with authoring rights on one weblog read, modify, or delete resources belonging to another weblog via unscoped identifier lookups. The issue affects multi-user installations where users author separate weblogs. CVSS 3.1 is 7.7 (AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:L), and the project rated it important. No exploitation in the wild is reported.
48