CVE-2026-82376

high

Description

Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a user with entry-editing rights on a weblog to cause the server to parse an attacker-influenced trackback response with an XML parser that does not disable external entity resolution, leading to disclosure of files readable by the Roller process. The Trackback control is hidden in the standard UI, but its action remains directly reachable, and no non-default server configuration is required. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which removes the outbound trackback response parser.

References

https://lists.apache.org/thread/dxqmd3873q87h06xpjjc9lnvp4jblz0l

https://github.com/apache/roller/pull/163

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88135

http://www.openwall.com/lists/oss-security/2026/09/25/9

Details

Source: Mitre, NVD

Published: 2026-09-28

Updated: 2026-09-29

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 7.7

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Severity: High

EPSS

EPSS: 0.00296