Description
Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a weblog administrator to read files readable by the Roller process and reach internal network addresses by importing a crafted OPML document, because the bookmark import parser does not disable external entity resolution. No non-default configuration is required; the import is reached through the administrator bookmark-import action. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which uses a hardened parser that disables external entities and document type declarations.
Published: 2026-09-28
Score: 7.7 High
EPSS: n/a
KEV: No
Impact: Information Disclosure and Internal Network Access
Action: Immediate Patch
AI Analysis

Impact

Apache Roller’s XML parser accepts external entity references in OPML files when an administrator imports bookmarks. A crafted OPML document can include entities that read arbitrary files readable by the Roller process and points to internal network addresses, enabling a privileged administrator to expose sensitive data and potentially pivot into the internal network. The vulnerability is not a classic remote code execution flaw, but it does allow a logged‑in administrator to read files beyond normal application boundaries and reach internal hosts.

Affected Systems

The flaw exists in Apache Roller 6.1.5 and earlier releases from the Apache Software Foundation. Users of these versions should check whether they are running the affected code base and plan an upgrade.

Risk and Exploitability

The CVSS score of 7.7 categorises this as High severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires administrative access to the bookmark‑import function and no special configuration is required, making the attack vector straightforward for an authorised user or an attacker who has compromised an administrator account.

Generated by OpenCVE AI on September 28, 2026 at 09:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Roller to version 6.1.6 or later, which uses a hardened parser that disallows external entities
  • Configure the XML parser to reject external entity references and document type declarations if your current installation does not already enforce these restrictions
  • Until the patch is applied, disable or restrict the bookmark‑import feature for administrators and monitor the system for anomalous OPML uploads

Generated by OpenCVE AI on September 28, 2026 at 09:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
References

Mon, 28 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a weblog administrator to read files readable by the Roller process and reach internal network addresses by importing a crafted OPML document, because the bookmark import parser does not disable external entity resolution. No non-default configuration is required; the import is reached through the administrator bookmark-import action. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which uses a hardened parser that disables external entities and document type declarations.
Title Apache Roller: XML external entity processing in OPML bookmark import
Weaknesses CWE-611
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-28T08:21:49.840Z

Reserved: 2026-08-28T20:55:50.657Z

Link: CVE-2026-82386

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T08:16:42.527

Modified: 2026-09-28T09:17:06.843

Link: CVE-2026-82386

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T09:45:11Z

Weaknesses
  • CWE-611

    Improper Restriction of XML External Entity Reference