CVE-2026-82377: Apache Roller: Missing weblog authorization in XML-RPC Blogger/MetaWeblog handlers
Apache Roller 6.1.5 lets authenticated users read, modify, or delete other weblogs via XML-RPC.
Apache disclosed CVE-2026-82377 in Apache Roller 6.1.5. Missing authorization in the legacy XML-RPC Blogger and MetaWeblog handlers lets an authenticated user read, modify, or delete content belonging to other weblogs. The handlers authenticate the caller but do not verify permission on the target weblog. CVSS 3.1 is 9.9 (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H), while the project labeled severity moderate. Exploitation in the wild is not reported.
56