CVE-2026-82380: Apache Roller: CSRF protection bypass via self-generated salt validation
Apache Roller 6.1.5 CSRF filters accept requests without the salt token, enabling forged state-changing actions.
Apache Roller 6.1.5 has a cross-site request forgery flaw, CVE-2026-82380, rated Important with a CVSS 3.1 score of 8.1. CSRF validation filters accept a request that does not submit the required salt token, so a remote attacker can cause a logged-in user to perform state-changing actions under that user's authority. The vector is network, low complexity, and no privileges, but it requires user interaction; confidentiality is unaffected while integrity and availability impacts are high. Only version 6.1.5 is listed as affected, and exploitation in the wild is not reported.
- CVE-2026-82380 affects Apache Roller 6.1.5 only.
- CSRF checks accept requests that omit the required salt token.
- CVSS 3.1 is 8.1; the vendor rates it Important.
- A remote attacker needs a logged-in victim and user interaction.
Vulnerabilities mentionedAll →
- published —
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-82380 | NVD description · AI analysis pending | — | — | — | — | — |
Posted by David M. Johnson on Sep 25 Severity: Important CVSS 3.1: 8.1 (high) CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H Affected versions: - Apache Roller 6.1.5 Description: Cross-Site Request Forgery (CSRF) in Apache Roller 6.1.5 allows a remote attacker to cause a logged-in user to perform state-changing actions under the victim's authority, because the CSRF validation filters accept a request that does not submit the required salt token, validating instead...
This source does not provide full text. Read it at seclists.org.