Description
Missing Authentication for Critical Function in Apache Roller 6.1.5 allows an unauthenticated remote attacker to persistently change a site-global configuration value (the frontpage weblog selection) on any installed instance, because the setup action remains anonymously reachable after installation and persists configuration without an authorization check. No optional feature or non-default configuration is required; the result can redirect or break the site's public frontpage, with administrative recovery available. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which restricts the write to global administrators.
Published: 2026-09-28
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: Remote configuration tampering
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a missing authentication check on the setup action of Apache Roller 6.1.5, classified as CWE‑306. Because the setup endpoint remains reachable after installation, an unauthenticated remote user can continuously change the global configuration that selects the frontpage weblog. This can redirect site visitors to a malicious page or break the public frontpage, while only requiring plain HTTP requests. Administrative recovery is possible by reverting the configuration, but the attack can persist until the system is patched.

Affected Systems

Affected systems are deployments of Apache Roller version 6.1.5. Upgrading to version 6.1.6 or newer limits write access on the setup action to global administrators, eliminating the flaw. No other product or version is listed in the CNA data.

Risk and Exploitability

The CVSS score of 8.2 indicates high severity, and the vulnerability is exploitable remotely without any authentication or special configuration. Because the EPSS score is unavailable and the issue is not yet in the CISA KEV catalog, there is no known exploitation data, but the attack vector is straightforward: any host running the affected version is at risk of remote configuration tampering. The lack of an authorization check allows an attacker to keep the change persistent, making remediation a high priority.

Generated by OpenCVE AI on September 28, 2026 at 09:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Apache Roller to version 6.1.6 or later to restrict setup writes to global administrators.
  • After the upgrade, review the frontpage weblog selection to ensure it reflects the desired page and correct any unintended changes.
  • Configure the web application or web server to restrict anonymous access to the `/setup` endpoint and other configuration endpoints, ensuring only authenticated users can reach them.

Generated by OpenCVE AI on September 28, 2026 at 09:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache roller
Vendors & Products Apache
Apache roller

Mon, 28 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
References

Mon, 28 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Description Missing Authentication for Critical Function in Apache Roller 6.1.5 allows an unauthenticated remote attacker to persistently change a site-global configuration value (the frontpage weblog selection) on any installed instance, because the setup action remains anonymously reachable after installation and persists configuration without an authorization check. No optional feature or non-default configuration is required; the result can redirect or break the site's public frontpage, with administrative recovery available. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which restricts the write to global administrators.
Title Apache Roller: Anonymous setup action allows frontpage configuration tampering
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-28T08:21:42.108Z

Reserved: 2026-08-28T20:46:20.615Z

Link: CVE-2026-82383

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T08:16:42.153

Modified: 2026-09-28T09:17:06.550

Link: CVE-2026-82383

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T11:00:12Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function