https://seclists.org/oss-sec/2026/q3/946: CVE-2026-82381: Apache Roller: Stod cross-site scripting in the authoring UI
Published Sep 25, 2026
·Updated
Affected Software
1 affected component
Apache Roller=6.1.5
Frequently Asked Questions
1
Which deployments are realistically exposed to this issue?
Deployments with weblogs that have multiple authors or administrators who are not mutually trusted are affected. No optional feature or non-default configuration is required.
2
What access does an attacker need to exploit it?
An attacker needs authoring rights on a weblog so they can store crafted content. The stored script executes when another author or administrator views the affected authoring UI.
3
What should teams do if they cannot upgrade immediately?
The provided information recommends upgrading to Apache Roller 6.1.6 or later. Until then, limit authoring access to mutually trusted users, since an author can target other authors or administrators through stored content.