CVE-2026-82376: Apache Roller: XML external entity processing in trackback response parser
Apache Roller 6.1.5 parses trackback responses with XXE enabled, exposing server files.
Apache disclosed CVE-2026-82376, an XML external entity flaw in Apache Roller 6.1.5. A user with entry-editing rights can cause the server to parse an attacker-influenced trackback response with a parser that does not disable external entity resolution, leading to file disclosure. CVSS 3.1 is 7.7 (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N), and the project rated it important. The advisory does not report exploitation in the wild.
- CVE-2026-82376 is an XXE flaw in Apache Roller 6.1.5.
- A weblog editor can influence a trackback response the server parses.
- External entity resolution is not disabled, enabling file disclosure.
- CVSS 3.1 is 7.7 with high confidentiality impact only.
- No active exploitation is stated.
Vulnerabilities mentionedAll →
- published —
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-82376 | NVD description · AI analysis pending | — | — | — | — | — |
Posted by David M. Johnson on Sep 25 Severity: Important CVSS 3.1: 7.7 (high) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N Affected versions: - Apache Roller 6.1.5 Description: Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a user with entry-editing rights on a weblog to cause the server to parse an attacker-influenced trackback response with an XML parser that does not disable external entity resolution, leading to disclosure of files...
This source does not provide full text. Read it at seclists.org.