CVE-2026-91206
Received Received - Intake

Reflected Cross-Site Scripting in Apache Roller

Vulnerability report for CVE-2026-91206, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: Apache Software Foundation

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a remote attacker to perform reflected cross-site scripting through the optional LDAP comment authenticator, which writes request parameter values into its HTML form without escaping. This affects only sites configured to use LdapCommentAuthenticator, and a victim whose session has already loaded the authenticator form must follow a crafted link. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which escapes the reflected values.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
apache roller to 6.1.6 (exc)
apache roller 6.1.6
apache roller 6.1.5

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a reflected cross-site scripting (XSS) vulnerability in Apache Roller 6.1.5. It occurs when the optional LDAP comment authenticator writes request parameter values into its HTML form without proper escaping. This allows a remote attacker to inject malicious scripts into web pages viewed by victims who have already loaded the authenticator form.

Detection Guidance

To detect this vulnerability, check if your Apache Roller instance is running version 6.1.5 and configured to use LdapCommentAuthenticator. Inspect the HTML forms for improperly escaped input fields in the LDAP comment authenticator. Look for reflected values in the rendered HTML that could indicate XSS vulnerabilities.

Impact Analysis

An attacker could trick a victim into following a crafted link, which would execute malicious scripts in the victim's browser. This could lead to theft of session cookies, account takeover, or unauthorized actions on behalf of the victim. The impact is limited to users whose sessions have already loaded the LDAP comment authenticator form.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive user data, which may violate GDPR's data protection requirements or HIPAA's security rules for protected health information. Organizations using affected versions may face compliance violations if user data is compromised through this XSS flaw.

Mitigation Strategies

Upgrade Apache Roller to version 6.1.6 or later to fix the XSS vulnerability. If upgrading is not immediately possible, disable the LdapCommentAuthenticator feature or restrict access to the affected forms until the upgrade is completed.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-91206. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart