Skip to content
feed: live
>_0dayNews
CVE Record
[ HIGH ]CVE-2026-82383

Apache Roller Missing Auth Lets Attackers Change Site Configuration

Missing authentication for a critical function in Apache Roller 6.1.5 allows an unauthenticated attacker to persistently change site-wide configuration. CVSS 8.2 high.

cat cve-2026-82383.json
Vendor
Apache Software Foundation
Product
Apache Roller
CVSS
8.2
EPSS (exploit probability)
0.5%
Status
patched
Published

CVE-2026-82383 is a missing authentication for critical function vulnerability in Apache Roller 6.1.5. An unauthenticated remote attacker can access a configuration endpoint that should require admin credentials and persistently change a site-global configuration value, specifically the frontpage weblog selection.

What to do: Upgrade Apache Roller to a patched version. See the NVD record and the Apache Roller GitHub fix.