CVE-2026-82387: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Software Foundation Apache Roller
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a user with media-upload rights to store active content on Roller's origin, because the media upload feature trusts the upload-supplied content type and serves the stored file back with that type. A victim who opens the uploaded file executes the stored script. Media uploads are disabled by default; only installations that enable them are affected, and the shipped type restrictions do not block active content once uploads are on. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which derives the stored type from file content and serves non-image media as a download.
AI Analysis
Technical Summary
This vulnerability in Apache Roller 6.1.5 involves improper neutralization of input during web page generation, specifically in the media upload feature. Users with media-upload rights can upload files containing active content because the system trusts the upload-supplied content type. When a victim opens such a file, the stored script executes, leading to a cross-site scripting condition. Media uploads are disabled by default, so only installations that enable this feature are affected. The shipped type restrictions do not prevent active content once uploads are enabled. The issue is fixed in Apache Roller 6.1.6, which improves type handling by deriving the stored type from file content and serving non-image media as downloads.
Potential Impact
An attacker with media-upload rights can store malicious active content on the server that executes in the context of a victim's browser when the uploaded file is accessed. This can lead to partial compromise of confidentiality and integrity (CVSS impact: low confidentiality and integrity impact, no availability impact). The vulnerability requires user interaction (opening the uploaded file) and privileges to upload media. Media uploads are disabled by default, limiting exposure.
Mitigation Recommendations
Users should upgrade to Apache Roller 6.1.6 or later, where the vulnerability is fixed by deriving the stored file type from file content and serving non-image media as downloads. If upgrading is not immediately possible, disabling media uploads will prevent exploitation since the feature is disabled by default. No other specific mitigations are indicated.
CVE-2026-82387: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Software Foundation Apache Roller
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a user with media-upload rights to store active content on Roller's origin, because the media upload feature trusts the upload-supplied content type and serves the stored file back with that type. A victim who opens the uploaded file executes the stored script. Media uploads are disabled by default; only installations that enable them are affected, and the shipped type restrictions do not block active content once uploads are on. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which derives the stored type from file content and serves non-image media as a download.
CVSS v3.1
Score 5.4medium
Affected software
Apache Software Foundation
Apache Roller
pkg:maven/org.apache.roller/rollerRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in Apache Roller 6.1.5 involves improper neutralization of input during web page generation, specifically in the media upload feature. Users with media-upload rights can upload files containing active content because the system trusts the upload-supplied content type. When a victim opens such a file, the stored script executes, leading to a cross-site scripting condition. Media uploads are disabled by default, so only installations that enable this feature are affected. The shipped type restrictions do not prevent active content once uploads are enabled. The issue is fixed in Apache Roller 6.1.6, which improves type handling by deriving the stored type from file content and serving non-image media as downloads.
Potential Impact
An attacker with media-upload rights can store malicious active content on the server that executes in the context of a victim's browser when the uploaded file is accessed. This can lead to partial compromise of confidentiality and integrity (CVSS impact: low confidentiality and integrity impact, no availability impact). The vulnerability requires user interaction (opening the uploaded file) and privileges to upload media. Media uploads are disabled by default, limiting exposure.
Mitigation Recommendations
Users should upgrade to Apache Roller 6.1.6 or later, where the vulnerability is fixed by deriving the stored file type from file content and serving non-image media as downloads. If upgrading is not immediately possible, disabling media uploads will prevent exploitation since the feature is disabled by default. No other specific mitigations are indicated.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- apache
- Date Reserved
- 2026-08-28T20:56:40.391Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aba1bc6f7a7c541065ca3da
Added to database: 09/28/2026, 07:48:22 UTC
Last enriched: 09/28/2026, 08:03:33 UTC
Last updated: 09/29/2026, 01:57:23 UTC
Views: 18
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.