CVE-2026-91206: Apache Roller: flected XSS in the optional LDAP comment authenticator
Published Sep 25, 2026
·Updated
Affected Software
1 affected component
Apache Roller
Frequently Asked Questions
1
Are deployments that do not use the optional LDAP comment authenticator affected?
The issue is identified in the optional LDAP comment authenticator, so deployments not using that authenticator are not indicated as affected by the available information.