CVE-2026-82380: Apache Roller: CSRF protection bypass via self-generated salt validation
Apache Roller 6.1.5 CSRF filters accept requests without the salt token, enabling forged state-changing actions.
Apache Roller 6.1.5 has a cross-site request forgery flaw, CVE-2026-82380, rated Important with a CVSS 3.1 score of 8.1. CSRF validation filters accept a request that does not submit the required salt token, so a remote attacker can cause a logged-in user to perform state-changing actions under that user's authority. The vector is network, low complexity, and no privileges, but it requires user interaction; confidentiality is unaffected while integrity and availability impacts are high. Only version 6.1.5 is listed as affected, and exploitation in the wild is not reported.
42