CVE-2026-82348

high

Description

Authorization Bypass Through User-Controlled Key in Apache Roller 6.1.5 allows an authenticated user with authoring rights on one weblog to read, modify, or delete resources belonging to another weblog through unscoped identifier-based lookups. This affects multi-user installations where users are intended to be isolated between weblogs; no optional feature or non-default configuration is required. A user with administrator rights on their weblog can also overwrite another weblog's Velocity template, whose content is evaluated when the victim weblog renders. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which scopes authoring resource lookups to the acting weblog.

References

https://lists.apache.org/thread/3h7zk8dhbt8fj5zdt8cjghx0b807wgy1

https://github.com/apache/roller/pull/162

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88129

http://www.openwall.com/lists/oss-security/2026/09/25/7

Details

Source: Mitre, NVD

Published: 2026-09-28

Updated: 2026-09-29

Risk Information

CVSS v2

Base Score: 6.1

Vector: CVSS2#AV:N/AC:H/Au:S/C:P/I:C/A:P

Severity: Medium

CVSS v3

Base Score: 7.7

Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:L

Severity: High

EPSS

EPSS: 0.00365