Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-82377: Apache Roller XML-RPC can let users edit other blogs
CVE-2026-82377 · published 12 days ago
Summary
Apache Roller version 6.1.5 lets anyone who can log in use the old XML‑RPC interface to view, change or delete posts that belong to other blogs, because it does not check whether the user has rights to those blogs. This only happens if the global XML‑RPC option is turned on, which is not the default. Upgrade to version 6.1.6 or later, or turn off the XML‑RPC feature, to stop the problem.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| apache software foundation | apache roller | 6.1.5 |
Original advisory text
Apache Roller: Missing weblog authorization in XML-RPC Blogger/MetaWeblog handlers
Missing Authorization in Apache Roller 6.1.5 allows an authenticated user to read, modify, or delete weblog content belonging to other weblogs through the legacy XML-RPC Blogger and MetaWeblog APIs, because the handlers authenticate the caller but do not verify the caller's permission on the weblog or entry actually affected. Only installations that enable the non-default global XML-RPC setting are affected; the per-weblog API flag defaults to enabled for UI-created weblogs. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which applies an explicit per-method permission check, or to keep the XML-RPC feature disabled.
References
- http://www.openwall.com/lists/oss-security/2026/09/25/10
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82377... Vendor Advisory
- https://lists.apache.org/thread/phxx56n0w6jjqzto2my3ot8hto0qjvn8
- https://nvd.nist.gov/vuln/detail/CVE-2026-82377 Vendor Advisory
- https://github.com/apache/roller/pull/164
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-862Missing Authorization
Timeline
Published28 Sep 2026
Updated9 Oct 2026
First seen28 Sep 2026
Track software like this
Free during beta