https://seclists.org/oss-sec/2026/q3/948: CVE-2026-82383: Apache Roller: Anonymous setup action allows frontpage configuration tampering

Published Sep 25, 2026
·
Updated

Affected Software

1 affected component
Apache Roller=6.1.5

Frequently Asked Questions

1

Who can exploit this issue?

Any unauthenticated remote attacker can exploit it against an installed Apache Roller 6.1.5 instance. No credentials, user interaction, optional feature, or non-default configuration are required.

2

What is the practical impact on an affected site?

An attacker can persistently change the site-global frontpage weblog selection. This can redirect the public frontpage or cause it to break; the issue does not affect confidentiality but has high integrity impact and low availability impact.

3

How can I determine whether my instance is affected?

Apache Roller 6.1.5 is identified as affected. An instance is affected if its setup action remains anonymously reachable after installation and can persist the frontpage weblog configuration without an authorization check.

4

What should be done if the frontpage has already been changed?

Administrative recovery is available to restore the intended frontpage configuration. Upgrade to Apache Roller 6.1.6 or later so that changes to this global setting are restricted to global administrators.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203