CVE-2026-82375: Apache Roller: Server-side request forgery via entry trackback and enclosure URLs

Published Sep 28, 2026
·
Updated

Server-Side Request Forgery (SSRF) in Apache Roller 6.1.5 allows an authenticated user with entry-editing rights on a weblog to cause outbound HTTP requests to attacker-chosen destinations through legacy outbound Trackback and entry enclosure handling. The Trackback control is hidden in the standard UI, but its action remains directly reachable; the enclosure path is relevant only when an author supplies an enclosure URL. No non-default server configuration is required, and the default empty Trackback allow-list permits all destinations. Requests can reach loopback and private-network addresses, while enclosure handling exposes response status, content type, and length. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which removes the outbound trackback action and stops dereferencing enclosure URLs.

Affected Software

1 affected component
Apache Roller=6.1.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Apache Roller to a version that resolves this vulnerability.

    Fixed in 6.1.6

Event History

Sep 28, 2026
CVE Published
via MITRE·07:46 AM
Data Sourced
via MITRE·07:46 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which users can trigger the vulnerable requests?

An authenticated user must have entry-editing rights on a weblog. No user interaction is required.

2

Are standard deployments exposed without additional configuration?

Yes. No non-default server configuration is required, and the default empty Trackback allow-list permits all destinations.

3

What internal targets and response information may be exposed?

Requests can reach loopback and private-network addresses. For enclosure URLs supplied by an author, the handling exposes the response status, content type, and length.

4

What version should be deployed to remediate the issue?

Upgrade to Apache Roller 6.1.6 or later. That release removes the outbound Trackback action and stops dereferencing enclosure URLs.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203