https://seclists.org/oss-sec/2026/q3/942: CVE-2026-82377: Apache Roller: Missing weblog authorization in XML-RPC Blogger/MetaWeblog handlers
Published Sep 25, 2026
·Updated
Affected Software
1 affected component
Apache Roller=6.1.5
Frequently Asked Questions
1
Which deployments are exposed to this issue?
Only Apache Roller 6.1.5 installations with the non-default global XML-RPC setting enabled are affected. The per-weblog API flag is enabled by default for weblogs created through the UI, but it is not sufficient on its own to expose an installation unless the global XML-RPC feature is enabled.
2
What level of access does an attacker need?
An attacker needs to authenticate as a Roller user. The vulnerable Blogger and MetaWeblog XML-RPC handlers do not verify that the authenticated user is authorized for the target weblog or entry.
3
What can an unauthorized authenticated user do?
They can read, modify, or delete weblog content belonging to other weblogs through the legacy XML-RPC Blogger and MetaWeblog APIs.
4
What should be done if an immediate upgrade is not possible?
Keep the XML-RPC feature disabled. Upgrading to Apache Roller 6.1.6 or later adds explicit per-method permission checks.