Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-82377: Apache Roller XML-RPC can let users edit other blogs

CVE-2026-82377 · published 12 days ago
Summary

Apache Roller version 6.1.5 lets anyone who can log in use the old XML‑RPC interface to view, change or delete posts that belong to other blogs, because it does not check whether the user has rights to those blogs. This only happens if the global XML‑RPC option is turned on, which is not the default. Upgrade to version 6.1.6 or later, or turn off the XML‑RPC feature, to stop the problem.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
apache software foundation apache roller 6.1.5
Original advisory text
Apache Roller: Missing weblog authorization in XML-RPC Blogger/MetaWeblog handlers
Missing Authorization in Apache Roller 6.1.5 allows an authenticated user to read, modify, or delete weblog content belonging to other weblogs through the legacy XML-RPC Blogger and MetaWeblog APIs, because the handlers authenticate the caller but do not verify the caller's permission on the weblog or entry actually affected. Only installations that enable the non-default global XML-RPC setting are affected; the per-weblog API flag defaults to enabled for UI-created weblogs. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which applies an explicit per-method permission check, or to keep the XML-RPC feature disabled.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.9 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-862Missing Authorization
Timeline
Published28 Sep 2026
Updated9 Oct 2026
First seen28 Sep 2026
Sources
CVE-2026-82377 · MITRE
Track software like this
Free during beta