CVE-2026-82546 Details
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows an unauthenticated remote attacker to store a crafted comment-author URL through the incoming Trackback endpoint when a published entry accepts comments and Trackbacks. The shipped Trackback, verification and moderation defaults allow the value to be approved and rendered as an active link; a visitor who clicks the link executes script in the weblog's origin. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which removes incoming Trackback support and suppresses non-HTTP(S) comment-author links. Users unable to upgrade should disable Trackbacks and remove untrusted Trackback comments.
A stored cross-site scripting vulnerability has been identified in Apache Roller version 6.1.5. This issue allows an unauthenticated remote attacker to inject a malicious comment-author URL through the Trackback endpoint of a published entry that accepts comments and Trackbacks. The default Trackback settings in Roller 6.1.5 automatically approve and render these URLs as active links. When clicked, these links execute scripts in the context of the weblog's origin.
Users are advised to upgrade to Apache Roller version 6.1.6 or later, which removes support for incoming Trackbacks and blocks non-HTTP(S) comment-author links. Those unable to upgrade should disable Trackbacks and delete untrusted Trackback comments.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 28, 2026CISA-ADP
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/09/25/21 | CVE | AdvisoryMailing ListRemedy |
| https://github.com/apache/roller/pull/178 | [email protected] | Issue TrackingVendor |
| https://lists.apache.org/thread/ddrykzvs67zpmzwsbqyfjmlydboln8x1 | [email protected] | AdvisoryMailing ListRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Apache Roller | 6.1.5 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | CVE Modified | CISA-ADP |
| Sep 28, 2026 | CVE Modified | CVE |
| Sep 28, 2026 | New CVE Received | [email protected] |
Volerion