https://seclists.org/oss-sec/2026/q3/948: CVE-2026-82383: Apache Roller: Anonymous setup action allows frontpage configuration tampering
Affected Software
Frequently Asked Questions
Who can exploit this issue?
Any unauthenticated remote attacker can exploit it against an installed Apache Roller 6.1.5 instance. No credentials, user interaction, optional feature, or non-default configuration are required.
What is the practical impact on an affected site?
An attacker can persistently change the site-global frontpage weblog selection. This can redirect the public frontpage or cause it to break; the issue does not affect confidentiality but has high integrity impact and low availability impact.
How can I determine whether my instance is affected?
Apache Roller 6.1.5 is identified as affected. An instance is affected if its setup action remains anonymously reachable after installation and can persist the frontpage weblog configuration without an authorization check.
What should be done if the frontpage has already been changed?
Administrative recovery is available to restore the intended frontpage configuration. Upgrade to Apache Roller 6.1.6 or later so that changes to this global setting are restricted to global administrators.