Description
Cross-Site Request Forgery (CSRF) in Apache Roller 6.1.5 allows a remote attacker to cause a logged-in user to perform state-changing actions under the victim's authority, because the CSRF validation filters accept a request that does not submit the required salt token, validating instead against a value the server itself generated for the request. No optional feature or non-default configuration is required; any logged-in author or administrator is affected when induced to visit a crafted page. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which validates only the submitted salt and applies the same check to multipart forms.
Published: 2026-09-28
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized state change via CSRF
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a CSRF bypass in Apache Roller 6.1.5. The framework’s CSRF filters accept a request that omits the required salt token, instead validating against a server‑generated value. An attacker can force a logged‑in user to visit a crafted page, causing the user to perform state‑changing actions under the victim’s authority. This weakness is classified as CWE‑352.

Affected Systems

Apache Software Foundation’s Apache Roller content management system. Version 6.1.5 is affected; upgrading to 6.1.6 or later mitigates the issue.

Risk and Exploitability

The CVSS score of 8.1 indicates a high severity. The EPSS score is not available, so no current exploitation probability can be quantified, and the vulnerability is not in the CISA KEV catalog. The attack requires a remote attacker to host a malicious page that a logged‑in author or administrator visits; no special configuration is needed. The attacker can then trigger any state‑changing request that would normally be protected by a CSRF token.

Generated by OpenCVE AI on September 28, 2026 at 09:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Roller to version 6.1.6 or later
  • Ensure all privileged actions require a submitted CSRF token and verify that multipart form handling validates the token
  • If an upgrade cannot be applied immediately, temporarily restrict authenticated users’ access to state‑changing endpoints or require re‑authentication for sensitive actions
  • Monitor HTTP POST traffic for unexpected or missing CSRF tokens as a detection mechanism

Generated by OpenCVE AI on September 28, 2026 at 09:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache roller
Vendors & Products Apache
Apache roller

Mon, 28 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
References

Mon, 28 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) in Apache Roller 6.1.5 allows a remote attacker to cause a logged-in user to perform state-changing actions under the victim's authority, because the CSRF validation filters accept a request that does not submit the required salt token, validating instead against a value the server itself generated for the request. No optional feature or non-default configuration is required; any logged-in author or administrator is affected when induced to visit a crafted page. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which validates only the submitted salt and applies the same check to multipart forms.
Title Apache Roller: CSRF protection bypass via self-generated salt validation
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-28T13:31:30.215Z

Reserved: 2026-08-28T20:44:39.957Z

Link: CVE-2026-82380

cve-icon Vulnrichment

Updated: 2026-09-28T08:21:34.290Z

cve-icon NVD

Status : Deferred

Published: 2026-09-28T08:16:41.787

Modified: 2026-09-28T14:29:44.860

Link: CVE-2026-82380

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T10:00:11Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)