Apache Roller 6.1.6 fixes 18 security vulnerabilities. Apache Roller
6.1.5 is affected. Upgrade to 6.1.6 now.

Every installation should upgrade. Some vulnerabilities need no optional
feature.
Vulnerabilities were found in these features:

- Comments & Trackbacks, LDAP comment authentication
- Multiple users and weblogs
- Media file uploads
- The frontpage theme
- XML-RPC (MetaWeblog or Blogger API), even when disabled
- AtomPub with WSSE authentication
- OAuth

Critical:
- CVE-2026-82384: Unauthenticated XML-RPC deserialization

Important:
- CVE-2026-82348: Cross-weblog resource tampering
- CVE-2026-82376: XXE in trackback parser
- CVE-2026-82380: CSRF protection bypass
- CVE-2026-82381: Stored XSS in authoring UI
- CVE-2026-82383: Anonymous setup tampering
- CVE-2026-82385: Velocity template sandbox escape
- CVE-2026-82386: XXE in OPML import
- CVE-2026-86507: Stored XSS in comment moderation

Moderate:
- CVE-2026-82375: SSRF via trackback and enclosure
- CVE-2026-82377: Missing XML-RPC weblog authorization
- CVE-2026-82378: OAuth endpoint trusts request identity
- CVE-2026-82379: WSSE authentication replay
- CVE-2026-82382: Reflected XSS in frontpage
- CVE-2026-82387: Stored XSS via media type
- CVE-2026-82546: Stored XSS via trackback links
- CVE-2026-91204: Stored javascript: URI in comments
- CVE-2026-91206: Reflected XSS in LDAP authenticator

Each advisory is in the [email protected] archive:
https://lists.apache.org/[email protected]

Downloads: https://roller.apache.org/downloads/downloads.html

Dave Johnson, on behalf of the Apache Roller project

Reply via email to