Skip to main content
EPSS 0.2%top 93%

CVE-2026-82387: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Software Foundation Apache Roller

0
Medium
VulnerabilityCVE-2026-82387cvecve-2026-82387cwe-79
Published: 09/28/2026 (09/28/2026, 07:36:12 UTC)
Source: CVE Database V5
Vendor/Project: Apache Software Foundation
Product: Apache Roller

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a user with media-upload rights to store active content on Roller's origin, because the media upload feature trusts the upload-supplied content type and serves the stored file back with that type. A victim who opens the uploaded file executes the stored script. Media uploads are disabled by default; only installations that enable them are affected, and the shipped type restrictions do not block active content once uploads are on. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which derives the stored type from file content and serves non-image media as a download.

CVSS v3.1

Score 5.4medium

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Affected software

Apache Software Foundation

Apache Roller

Affected versions
=6.1.5
org.apache.roller/roller
pkg:maven/org.apache.roller/roller
Affected versions
=6.1.5

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/28/2026, 08:03:33 UTC

Technical Analysis

This vulnerability in Apache Roller 6.1.5 involves improper neutralization of input during web page generation, specifically in the media upload feature. Users with media-upload rights can upload files containing active content because the system trusts the upload-supplied content type. When a victim opens such a file, the stored script executes, leading to a cross-site scripting condition. Media uploads are disabled by default, so only installations that enable this feature are affected. The shipped type restrictions do not prevent active content once uploads are enabled. The issue is fixed in Apache Roller 6.1.6, which improves type handling by deriving the stored type from file content and serving non-image media as downloads.

Potential Impact

An attacker with media-upload rights can store malicious active content on the server that executes in the context of a victim's browser when the uploaded file is accessed. This can lead to partial compromise of confidentiality and integrity (CVSS impact: low confidentiality and integrity impact, no availability impact). The vulnerability requires user interaction (opening the uploaded file) and privileges to upload media. Media uploads are disabled by default, limiting exposure.

Mitigation Recommendations

Users should upgrade to Apache Roller 6.1.6 or later, where the vulnerability is fixed by deriving the stored file type from file content and serving non-image media as downloads. If upgrading is not immediately possible, disabling media uploads will prevent exploitation since the feature is disabled by default. No other specific mitigations are indicated.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
apache
Date Reserved
2026-08-28T20:56:40.391Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6aba1bc6f7a7c541065ca3da

Added to database: 09/28/2026, 07:48:22 UTC

Last enriched: 09/28/2026, 08:03:33 UTC

Last updated: 09/29/2026, 01:57:23 UTC

Views: 18

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses