https://seclists.org/oss-sec/2026/q3/956: CVE-2026-91206: Apache Roller: flected XSS in the optional LDAP comment authenticator
Published Sep 25, 2026
·Updated
Affected Software
1 affected component
Apache Roller=6.1.5
Frequently Asked Questions
1
Which deployments are exposed?
Only Apache Roller 6.1.5 sites configured to use LdapCommentAuthenticator are affected. Sites not using this optional LDAP comment authenticator are not affected by this issue.
2
What must happen for exploitation to succeed?
An attacker must induce a victim to follow a crafted link. The victim's session must already have loaded the LDAP comment authenticator form.
3
Is authentication required for the attacker?
No. The CVSS vector lists privileges required as none, although exploitation requires user interaction from a victim.
4
What should be done if the affected authenticator is in use?
Upgrade Apache Roller to version 6.1.6 or later. The fixed versions escape the reflected request parameter values in the form.