CVE-2026-82348 HIGH

CVE-2026-82348: Apache Roller: Cross-weblog resource tampering via unscoped authoring lookups

Vendor Apache Software Foundation
Product Apache Roller
Weakness CWE-639 · IDOR
Published September 28, 2026
Last update September 28, 2026

CVSS base score

7.7/10
Attack vector Network
Attack complexity High
Privileges required Low
User interaction None
Confidentiality Low
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:L

What the vulnerability does

01Description

Authorization Bypass Through User-Controlled Key in Apache Roller 6.1.5 allows an authenticated user with authoring rights on one weblog to read, modify, or delete resources belonging to another weblog through unscoped identifier-based lookups. This affects multi-user installations where users are intended to be isolated between weblogs; no optional feature or non-default configuration is required. A user with administrator rights on their weblog can also overwrite another weblog's Velocity template, whose content is evaluated when the victim weblog renders. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which scopes authoring resource lookups to the acting weblog.

Key dates

02Disclosure timeline

September 28, 2026 CVE published

Related vulnerabilities

04Related CVE