CVE-2026-82381
Received Received - Intake

Stored XSS in Apache Roller Weblog

Vulnerability report for CVE-2026-82381, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: Apache Software Foundation

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a user with authoring rights on a weblog to store crafted content that is later written into the authoring UI's JavaScript string literals and markup sinks without proper encoding, causing the stored script to execute in another author's or administrator's browser. No optional feature or non-default configuration is required; this affects weblogs with multiple authors or administrators who are not mutually trusted. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which moves those values out of JavaScript literals and writes them as text.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
apache roller to 6.1.6 (exc)
apache roller 6.1.6

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Cross-site Scripting (XSS) vulnerability in Apache Roller 6.1.5. It allows a user with authoring rights to store malicious content that gets executed in another user's or administrator's browser when they view the affected UI elements. The issue occurs because user-controlled input is improperly embedded into JavaScript string literals and markup without proper encoding.

Detection Guidance

To detect this vulnerability, inspect Apache Roller instances for outdated versions (6.1.5 or earlier). Check for user-generated content containing JavaScript in web pages, especially in authoring UI sections. Review server logs for suspicious input patterns like angle brackets or quotes in user-submitted data.

Impact Analysis

If you are an administrator or another author using the same Apache Roller instance, this vulnerability could allow an attacker to execute malicious scripts in your browser. This might lead to session hijacking, unauthorized actions on your behalf, or theft of sensitive data like cookies or credentials.

Compliance Impact

This XSS vulnerability could compromise data confidentiality and integrity, which are key requirements under GDPR and HIPAA. It may lead to unauthorized access to personal data, violating compliance obligations for data protection and security.

Mitigation Strategies

Upgrade Apache Roller to version 6.1.6 or later immediately. This version refactors inline JavaScript handlers to use data attributes and ensures proper escaping of user input. Verify the upgrade by testing authoring UI functionality and confirming no unsafe values remain in JavaScript literals.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82381. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart