CVE-2026-82377: Apache Roller: Missing weblog authorization in XML-RPC Blogger/MetaWeblog handlers
Apache Roller 6.1.5 lets authenticated users read, modify, or delete other weblogs via XML-RPC.
Apache disclosed CVE-2026-82377 in Apache Roller 6.1.5. Missing authorization in the legacy XML-RPC Blogger and MetaWeblog handlers lets an authenticated user read, modify, or delete content belonging to other weblogs. The handlers authenticate the caller but do not verify permission on the target weblog. CVSS 3.1 is 9.9 (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H), while the project labeled severity moderate. Exploitation in the wild is not reported.
- CVE-2026-82377 affects Apache Roller 6.1.5.
- Authenticated users can read, modify, or delete other weblogs.
- Legacy Blogger and MetaWeblog XML-RPC handlers skip permission checks.
- CVSS 3.1 is 9.9; the project rated it moderate.
- No in-the-wild exploitation is reported.
Vulnerabilities mentionedAll →
- published —
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-82377 | NVD description · AI analysis pending | — | — | — | — | — |
Posted by David M. Johnson on Sep 25 Severity: Moderate CVSS 3.1: 9.9 (critical) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Affected versions: - Apache Roller 6.1.5 Description: Missing Authorization in Apache Roller 6.1.5 allows an authenticated user to read, modify, or delete weblog content belonging to other weblogs through the legacy XML-RPC Blogger and MetaWeblog APIs, because the handlers authenticate the caller but do not verify the caller's permission on...
This source does not provide full text. Read it at seclists.org.