7.7
CVE-2026-82348
- EPSS 0.37%
- Veröffentlicht 28.09.2026 07:36:45
- Zuletzt bearbeitet 29.09.2026 15:17:29
- Erkennungen
Apache Roller: Cross-weblog resource tampering via unscoped authoring lookups
Authorization Bypass Through User-Controlled Key in Apache Roller 6.1.5 allows an authenticated user with authoring rights on one weblog to read, modify, or delete resources belonging to another weblog through unscoped identifier-based lookups. This affects multi-user installations where users are intended to be isolated between weblogs; no optional feature or non-default configuration is required. A user with administrator rights on their weblog can also overwrite another weblog's Velocity template, whose content is evaluated when the victim weblog renders. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which scopes authoring resource lookups to the acting weblog.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerApache Software Foundation
≫
Produkt
Apache Roller
Default Statusunknown
Version
6.1.5
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.37% | 0.278 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Apache | 7.7 | 1.8 | 5.3 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:L
|
CWE-639 Authorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
https://github.com/apache/roller/pull/162
https://lists.apache.org/thread/3h7zk8dhbt8fj5zdt8cjghx0b807wgy1
http://www.openwall.com/lists/oss-security/2026/09/25/7