CVE-2026-82348
Received Received - Intake

Authorization Bypass in Apache Roller via Unscoped Key Lookups

Vulnerability report for CVE-2026-82348, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: Apache Software Foundation

Description

Authorization Bypass Through User-Controlled Key in Apache Roller 6.1.5 allows an authenticated user with authoring rights on one weblog to read, modify, or delete resources belonging to another weblog through unscoped identifier-based lookups. This affects multi-user installations where users are intended to be isolated between weblogs; no optional feature or non-default configuration is required. A user with administrator rights on their weblog can also overwrite another weblog's Velocity template, whose content is evaluated when the victim weblog renders. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which scopes authoring resource lookups to the acting weblog.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
apache roller 6.1.5
apache roller From 6.1.6 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an authorization bypass in Apache Roller 6.1.5 where an authenticated user with authoring rights on one weblog can access, modify, or delete resources belonging to another weblog. This occurs due to unscoped identifier-based lookups, allowing cross-weblog access without proper isolation. The issue affects multi-user installations where users should be isolated between weblogs.

Detection Guidance

To detect CVE-2026-82348, check Apache Roller version. If running 6.1.5, the system is vulnerable. Verify if unscoped identifier-based lookups exist in resource management APIs. Look for unauthorized access attempts between weblogs or template modifications by non-owners.

Impact Analysis

If you use Apache Roller 6.1.5 in a multi-user setup, an attacker with authoring rights on one weblog could read, edit, or delete content on another weblog. An administrator could even overwrite a Velocity template, which executes when the victim weblog renders, potentially leading to further compromise.

Compliance Impact

This vulnerability could lead to unauthorized access or modification of sensitive data, violating confidentiality and integrity requirements under GDPR and HIPAA. Unauthorized data exposure or alteration may result in non-compliance, legal penalties, or reputational damage.

Mitigation Strategies

Upgrade Apache Roller to version 6.1.6 or later to scope authoring resource lookups to the acting weblog and prevent unauthorized access between weblogs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82348. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart