CVE-2026-82386: Apache Roller: XML external entity processing in OPML bookmark import
Apache Roller 6.1.5 lets weblog admins read local files via XXE in OPML imports.
Apache disclosed CVE-2026-82386, an XML external entity flaw in Apache Roller 6.1.5 rated Important with CVSS 3.1 7.7. A weblog administrator can import a crafted OPML document because the bookmark import parser does not disable external entities. The flaw can expose files readable by the Roller process and allow requests to internal network addresses. No exploitation in the wild is reported.
48