CVE-2026-82383: Apache Roller: Anonymous setup action allows frontpage configuration tampering
Apache Roller 6.1.5 lets unauthenticated attackers persistently change the site frontpage weblog selection.
Apache disclosed CVE-2026-82383 in Apache Roller 6.1.5, rated Important with CVSS 3.1 8.2. Missing authentication lets an unauthenticated remote attacker persistently change the site-global frontpage weblog selection because the setup action remains reachable after installation. Impact is high integrity and low availability, with no confidentiality loss. The advisory does not report exploitation in the wild.
46