CVE-2026-82377

LOWCVSS 9.9 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Missing Authorization in Apache Roller 6.1.5 allows an authenticated user to read, modify, or delete weblog content belonging to other weblogs through the legacy XML-RPC Blogger and MetaWeblog APIs, because the handlers authenticate the caller but do not verify the caller's permission on the weblog or entry actually affected. Only installations that enable the non-default global XML-RPC setting are affected; the per-weblog API flag defaults to enabled for UI-created weblogs. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which applies an explicit per-method permission check, or to keep the XML-RPC feature disabled.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-28: 109-28
Full discourse1 post
  • Upwind Security MDR@UpwindMDR

    🚨 Critical - Apache Roller XML-RPC RCE and Authorization Bypass (CVE-2026-82384, CVE-2026-82377) Apache Roller 6.1.5 has two serious XML-RPC flaws: CVE-2026-82384 allows unauthenticated attackers to trigger pre-auth deserialization of attacker-controlled data, potentially leading to RCE, even when global XML-RPC is disabled. CVE-2026-82377 allows authenticated users to read, modify, or delete content in other weblogs when global XML-RPC is enabled, due to missing per-weblog authorization checks. 👉 Affected: Apache Roller 6.1.5 | Upgrade to 6.1.6

    0000032
    308 followersView on X

Explore more