CVE-2026-91206: Apache Roller: Reflected XSS in the optional LDAP comment authenticator
Apache Roller 6.1.5 has a moderate reflected XSS in its optional LDAP comment authenticator.
Apache disclosed CVE-2026-91206, a reflected cross-site scripting flaw in Apache Roller 6.1.5. The optional LDAP comment authenticator writes request parameter values into its HTML form without proper neutralization. Apache rates it moderate, with CVSS 3.1 6.1 (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). Exploitation requires a victim to interact with a crafted link; no in-the-wild use is described.
34