https://seclists.org/oss-sec/2026/q3/951: CVE-2026-82386: Apache Roller: XML external entity processing in OPML bookmark import
Published Sep 25, 2026
·Updated
Affected Software
1 affected component
Apache Roller=6.1.5
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs weblog administrator privileges to access the bookmark-import action and import a crafted OPML document. No user interaction beyond that administrator action is required.
2
Is a non-default configuration required for exploitation?
No. The vulnerable OPML bookmark-import functionality is reachable through the administrator bookmark-import action without any non-default configuration.
3
What could a successful exploit allow?
A malicious OPML document can cause the Roller process to read files that it can access and make requests to internal network addresses through external entity resolution.
4
What should be done if the deployment is affected?
Upgrade Apache Roller to version 6.1.6 or later. The updated version uses a hardened parser that disables external entities and document type declarations.