CVE-2026-82383: Apache Roller: Anonymous setup action allows frontpage configuration tampering
Published Sep 25, 2026
·Updated
Affected Software
1 affected component
Apache Roller
Frequently Asked Questions
1
Does exploitation require an authenticated Roller account?
No. The affected setup action is described as anonymous, so an attacker would not need to authenticate to use it.