CVE-2026-82348: Apache Roller: Cross-weblog resource tampering via unscoped authoring lookups
Apache Roller 6.1.5 lets one weblog's authors tamper with another weblog's resources.
Apache disclosed CVE-2026-82348 in Apache Roller 6.1.5. An authorization bypass through a user-controlled key lets an authenticated user with authoring rights on one weblog read, modify, or delete resources belonging to another weblog via unscoped identifier lookups. The issue affects multi-user installations where users author separate weblogs. CVSS 3.1 is 7.7 (AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:L), and the project rated it important. No exploitation in the wild is reported.
- CVE-2026-82348 is an authorization bypass in Apache Roller 6.1.5.
- Authors can read, modify, or delete another weblog's resources.
- Lookups use unscoped, user-controlled identifiers.
- It matters on multi-user installations with separate weblog authors.
- CVSS 3.1 is 7.7; exploitation is not reported.
Vulnerabilities mentionedAll →
- published —
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-82348 | NVD description · AI analysis pending | — | — | — | — | — |
Posted by David M. Johnson on Sep 25 Severity: Important CVSS 3.1: 7.7 (high) CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:L Affected versions: - Apache Roller 6.1.5 Description: Authorization Bypass Through User-Controlled Key in Apache Roller 6.1.5 allows an authenticated user with authoring rights on one weblog to read, modify, or delete resources belonging to another weblog through unscoped identifier-based lookups. This affects multi-user installations where users are...
This source does not provide full text. Read it at seclists.org.