CVE-2026-82376: Apache Roller: XML external entity processing in trackback response parser
Apache Roller 6.1.5 parses trackback responses with XXE enabled, exposing server files.
Apache disclosed CVE-2026-82376, an XML external entity flaw in Apache Roller 6.1.5. A user with entry-editing rights can cause the server to parse an attacker-influenced trackback response with a parser that does not disable external entity resolution, leading to file disclosure. CVSS 3.1 is 7.7 (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N), and the project rated it important. The advisory does not report exploitation in the wild.
46