CVE-2026-82387: Apache Roller: Stored cross-site scripting via uploaded media content type
Apache Roller 6.1.5 allows media uploaders to store XSS by spoofing content type, CVE-2026-82387.
Apache disclosed CVE-2026-82387, a stored cross-site scripting flaw in Apache Roller 6.1.5 with a CVSS 3.1 score of 5.4. A user who already has media-upload rights can store active content on the Roller origin because uploads trust the supplied content type and that content is then served. Exploitation requires low privileges and user interaction, with low confidentiality and integrity impact. No in-the-wild exploitation is reported.
- CVE-2026-82387 scores CVSS 3.1 5.4, moderate
- Attacker needs media-upload privileges on Apache Roller 6.1.5
- Upload feature trusts the client-supplied content type
- Served active content can execute as stored XSS after user interaction
Vulnerabilities mentionedAll →
- published —
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-82387 | NVD description · AI analysis pending | — | — | — | — | — |
Posted by David M. Johnson on Sep 25 Severity: Moderate CVSS 3.1: 5.4 (medium) CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N Affected versions: - Apache Roller 6.1.5 Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a user with media-upload rights to store active content on Roller's origin, because the media upload feature trusts the upload-supplied content type and serves the...
This source does not provide full text. Read it at seclists.org.