CVE-2026-82377
Received Received - Intake

Missing Authorization in Apache Roller

Vulnerability report for CVE-2026-82377, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: Apache Software Foundation

Description

Missing Authorization in Apache Roller 6.1.5 allows an authenticated user to read, modify, or delete weblog content belonging to other weblogs through the legacy XML-RPC Blogger and MetaWeblog APIs, because the handlers authenticate the caller but do not verify the caller's permission on the weblog or entry actually affected. Only installations that enable the non-default global XML-RPC setting are affected; the per-weblog API flag defaults to enabled for UI-created weblogs. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which applies an explicit per-method permission check, or to keep the XML-RPC feature disabled.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
apache roller to 6.1.6 (exc)
apache roller 6.1.6

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-82377 is a missing authorization vulnerability in Apache Roller 6.1.5. It allows an authenticated user to read, modify, or delete weblog content belonging to other users through the legacy XML-RPC Blogger and MetaWeblog APIs. The issue occurs because the handlers authenticate the caller but fail to verify if the caller has permission to access the specific weblog or entry they are trying to modify.

Detection Guidance

Check if Apache Roller 6.1.5 is running with XML-RPC enabled. Review logs for unauthorized access attempts to weblog content via XML-RPC Blogger or MetaWeblog APIs. Inspect network traffic for XML-RPC requests targeting Roller instances.

Impact Analysis

If you are using Apache Roller 6.1.5 with the non-default global XML-RPC setting enabled, an attacker with valid credentials could access, alter, or delete content on weblogs they do not own. This could lead to data breaches, unauthorized modifications, or loss of critical information. Users are advised to upgrade to Roller 6.1.6 or later or disable the XML-RPC feature to mitigate this risk.

Compliance Impact

This vulnerability could lead to unauthorized access and modification of sensitive data, violating confidentiality and integrity requirements under GDPR and HIPAA. GDPR requires strict access controls and data protection measures, while HIPAA mandates safeguards for protected health information. Exploitation of this flaw could result in non-compliance, legal penalties, and reputational damage.

Mitigation Strategies

Upgrade to Apache Roller 6.1.6 or later. Disable the global XML-RPC setting if not required. Ensure per-weblog API flags are enabled for UI-created weblogs. Apply explicit permission checks for weblog and entry operations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82377. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart