CVE-2026-82386 Details
Description
Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a weblog administrator to read files readable by the Roller process and reach internal network addresses by importing a crafted OPML document, because the bookmark import parser does not disable external entity resolution. No non-default configuration is required; the import is reached through the administrator bookmark-import action. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which uses a hardened parser that disables external entities and document type declarations.
A vulnerability in Apache Roller version 6.1.5 allows weblog administrators to read files accessible to the Roller process and access internal network addresses. This is achieved by importing a specially crafted OPML document, as the bookmark import parser fails to disable external entity resolution. The issue does not require any non-default configuration and can be exploited through the administrator's bookmark-import action.
Users are advised to upgrade to Apache Roller version 6.1.6 or later, which includes a revised parser that disables external entities and document type declarations.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 28, 2026CISA-ADP
Assessed Sep 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/09/25/19 | CVE | AdvisoryMailing ListRemedy |
| https://github.com/apache/roller/pull/173 | [email protected] | Issue TrackingVendor |
| https://lists.apache.org/thread/mrtstv8odj7l9mcrto445lftrcpw0sxl | [email protected] | AdvisoryMailing ListRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-611 | Improper Restriction of XML External Entity Reference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Apache Roller | 6.1.5 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 29, 2026 | CVE Modified | CISA-ADP |
| Sep 28, 2026 | CVE Modified | CVE |
| Sep 28, 2026 | New CVE Received | [email protected] |
Volerion