Impact
A missing authorization check in the legacy XML‑RPC Blogger and MetaWeblog handlers allows any authenticated user to read, modify, or delete weblog entries that belong to other weblogs. The handlers perform authentication of the caller but do not verify the caller’s permission for the target weblog or entry, enabling arbitrary manipulation of content on sites that expose the XML‑RPC interface.
Affected Systems
The flaw exists in Apache Roller 6.1.5 and earlier releases that enable the non‑default global XML‑RPC setting. The per‑weblog API flag defaults to enabled for UI‑created weblogs, meaning most typical installations are affected unless the global XML‑RPC functionality has been disabled. The vendor recommends upgrading to 6.1.6 or later, where an explicit per‑method permission check is applied, or disabling XML‑RPC entirely.
Risk and Exploitability
The CVSS score is 9.9, indicating critical severity, but EPSS data is not available. The issue is not listed in the CISA KEV catalog. Attackers need only an authenticated session to the server; if XML‑RPC is enabled, they can abuse the endpoint to manipulate any weblog content regardless of ownership. The lack of a permission gate means that privilege escalation to higher‑level content is possible within the scope of authentication.
OpenCVE Enrichment