CVE-2026-82386: Apache Roller: XML external entity processing in OPML bookmark import
Apache Roller 6.1.5 lets weblog admins read local files via XXE in OPML imports.
Apache disclosed CVE-2026-82386, an XML external entity flaw in Apache Roller 6.1.5 rated Important with CVSS 3.1 7.7. A weblog administrator can import a crafted OPML document because the bookmark import parser does not disable external entities. The flaw can expose files readable by the Roller process and allow requests to internal network addresses. No exploitation in the wild is reported.
- Affects Apache Roller 6.1.5
- Weblog administrator can import a crafted OPML file
- Parser does not disable XML external entities
- Can read process-readable files and reach internal addresses
- CVSS 3.1 base score 7.7
Vulnerabilities mentionedAll →
- published —
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-82386 | NVD description · AI analysis pending | — | — | — | — | — |
Posted by David M. Johnson on Sep 25 Severity: Important CVSS 3.1: 7.7 (high) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N Affected versions: - Apache Roller 6.1.5 Description: Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a weblog administrator to read files readable by the Roller process and reach internal network addresses by importing a crafted OPML document, because the bookmark import parser does not disable external entity...
This source does not provide full text. Read it at seclists.org.