CVE-2026-82383: Apache Roller: Anonymous setup action allows frontpage configuration tampering
Apache Roller 6.1.5 lets unauthenticated attackers persistently change the site frontpage weblog selection.
Apache disclosed CVE-2026-82383 in Apache Roller 6.1.5, rated Important with CVSS 3.1 8.2. Missing authentication lets an unauthenticated remote attacker persistently change the site-global frontpage weblog selection because the setup action remains reachable after installation. Impact is high integrity and low availability, with no confidentiality loss. The advisory does not report exploitation in the wild.
- CVE-2026-82383 affects Apache Roller 6.1.5 only.
- Unauthenticated attackers can change the global frontpage weblog selection.
- CVSS 3.1 is 8.2: high integrity, low availability, no confidentiality impact.
- The setup action remains anonymously reachable after installation.
Vulnerabilities mentionedAll →
- published —
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-82383 | NVD description · AI analysis pending | — | — | — | — | — |
Posted by David M. Johnson on Sep 25 Severity: Important CVSS 3.1: 8.2 (high) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L Affected versions: - Apache Roller 6.1.5 Description: Missing Authentication for Critical Function in Apache Roller 6.1.5 allows an unauthenticated remote attacker to persistently change a site-global configuration value (the frontpage weblog selection) on any installed instance, because the setup action remains anonymously reachable after...
This source does not provide full text. Read it at seclists.org.