Description
Missing Authorization in Apache Roller 6.1.5 allows an authenticated user to read, modify, or delete weblog content belonging to other weblogs through the legacy XML-RPC Blogger and MetaWeblog APIs, because the handlers authenticate the caller but do not verify the caller's permission on the weblog or entry actually affected. Only installations that enable the non-default global XML-RPC setting are affected; the per-weblog API flag defaults to enabled for UI-created weblogs. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which applies an explicit per-method permission check, or to keep the XML-RPC feature disabled.
Published: 2026-09-28
Score: 9.9 Critical
EPSS: n/a
KEV: No
Impact: Unauthorized Weblog Access
Action: Immediate Patch
AI Analysis

Impact

A missing authorization check in the legacy XML‑RPC Blogger and MetaWeblog handlers allows any authenticated user to read, modify, or delete weblog entries that belong to other weblogs. The handlers perform authentication of the caller but do not verify the caller’s permission for the target weblog or entry, enabling arbitrary manipulation of content on sites that expose the XML‑RPC interface.

Affected Systems

The flaw exists in Apache Roller 6.1.5 and earlier releases that enable the non‑default global XML‑RPC setting. The per‑weblog API flag defaults to enabled for UI‑created weblogs, meaning most typical installations are affected unless the global XML‑RPC functionality has been disabled. The vendor recommends upgrading to 6.1.6 or later, where an explicit per‑method permission check is applied, or disabling XML‑RPC entirely.

Risk and Exploitability

The CVSS score is 9.9, indicating critical severity, but EPSS data is not available. The issue is not listed in the CISA KEV catalog. Attackers need only an authenticated session to the server; if XML‑RPC is enabled, they can abuse the endpoint to manipulate any weblog content regardless of ownership. The lack of a permission gate means that privilege escalation to higher‑level content is possible within the scope of authentication.

Generated by OpenCVE AI on September 28, 2026 at 09:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Roller to version 6.1.6 or later, which implements per‑method permission checks.
  • If the XML‑RPC feature is not required, disable the global XML‑RPC setting to block the vulnerable handlers.
  • For existing weblogs, disable the per‑weblog API flag or set it explicitly to "disabled" to prevent accidental exposure of the legacy handlers.

Generated by OpenCVE AI on September 28, 2026 at 09:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache roller
Vendors & Products Apache
Apache roller

Mon, 28 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
References

Mon, 28 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization in Apache Roller 6.1.5 allows an authenticated user to read, modify, or delete weblog content belonging to other weblogs through the legacy XML-RPC Blogger and MetaWeblog APIs, because the handlers authenticate the caller but do not verify the caller's permission on the weblog or entry actually affected. Only installations that enable the non-default global XML-RPC setting are affected; the per-weblog API flag defaults to enabled for UI-created weblogs. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which applies an explicit per-method permission check, or to keep the XML-RPC feature disabled.
Title Apache Roller: Missing weblog authorization in XML-RPC Blogger/MetaWeblog handlers
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-28T08:21:26.381Z

Reserved: 2026-08-28T20:38:02.732Z

Link: CVE-2026-82377

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T08:16:41.417

Modified: 2026-09-28T09:17:05.977

Link: CVE-2026-82377

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T10:30:14Z

Weaknesses