CVE-2026-82387 Details
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a user with media-upload rights to store active content on Roller's origin, because the media upload feature trusts the upload-supplied content type and serves the stored file back with that type. A victim who opens the uploaded file executes the stored script. Media uploads are disabled by default; only installations that enable them are affected, and the shipped type restrictions do not block active content once uploads are on. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which derives the stored type from file content and serves non-image media as a download.
A stored cross-site scripting vulnerability has been identified in Apache Roller version 6.1.5. This issue arises from improper handling of input during web page generation. Users with media-upload rights can upload files that include active content, as the media upload feature accepts the content type provided by the user and serves the file with that type. When the uploaded file is opened, the stored script is executed. This vulnerability only affects installations that have enabled media uploads, which are disabled by default. Furthermore, the default type restrictions do not prevent active content from being executed once uploads are allowed.
Users are advised to upgrade to Apache Roller version 6.1.6 or later, which addresses this vulnerability by deriving the content type from the file's actual content and serving non-image media as a downloadable file.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 28, 2026CISA-ADP
Assessed Sep 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/09/25/20 | CVE | AdvisoryMailing ListRemedy |
| https://github.com/apache/roller/pull/174 | [email protected] | Issue TrackingVendor |
| https://lists.apache.org/thread/9h1d77xjjk6q90k7l8y7nyffg6ltdzxo | [email protected] | AdvisoryMailing ListRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Apache Roller | 6.1.5 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 29, 2026 | CVE Modified | CISA-ADP |
| Sep 28, 2026 | CVE Modified | CVE |
| Sep 28, 2026 | New CVE Received | [email protected] |
Volerion