CVE-2026-82387
Received Received - Intake

Stored XSS in Apache Roller Media Upload

Vulnerability report for CVE-2026-82387, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: Apache Software Foundation

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a user with media-upload rights to store active content on Roller's origin, because the media upload feature trusts the upload-supplied content type and serves the stored file back with that type. A victim who opens the uploaded file executes the stored script. Media uploads are disabled by default; only installations that enable them are affected, and the shipped type restrictions do not block active content once uploads are on. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which derives the stored type from file content and serves non-image media as a download.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
apache roller to 6.1.6 (exc)
apache roller 6.1.6

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Cross-site Scripting (XSS) vulnerability in Apache Roller 6.1.5. It occurs because the media upload feature trusts the content type provided during upload and serves the file back with that type. When a victim opens the uploaded file, any stored script executes. The vulnerability arises because media uploads are enabled and the system does not block active content types.

Detection Guidance

Check Apache Roller instances with media uploads enabled for files served with incorrect MIME types. Inspect uploaded media files for active content (e.g., JavaScript, CSS) served inline instead of as downloads. Review server logs for requests to uploaded media files with suspicious content types.

Impact Analysis

An attacker with media-upload rights could upload a malicious file that executes when opened by a victim. This could lead to unauthorized actions on behalf of the victim, data theft, or session hijacking. The impact depends on the victim's privileges and the content of the uploaded file.

Compliance Impact

This vulnerability could lead to data breaches, which may violate GDPR (data protection) and HIPAA (health information privacy) requirements. Unauthorized script execution could expose sensitive user data, resulting in non-compliance with these regulations.

Mitigation Strategies

Upgrade to Apache Roller 6.1.6 or later to enforce stricter content type handling. Disable media uploads if not required. Ensure uploaded files are served as downloads with X-Content-Type-Options: nosniff headers. Restrict uploads to predefined passive formats only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82387. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart