CVE Record
[ HIGH ]CVE-2026-82383
Apache Roller Missing Auth Lets Attackers Change Site Configuration
Missing authentication for a critical function in Apache Roller 6.1.5 allows an unauthenticated attacker to persistently change site-wide configuration. CVSS 8.2 high.
- Vendor
- Apache Software Foundation
- Product
- Apache Roller
- CVSS
- 8.2
- EPSS (exploit probability)
- 0.5%
- Status
- patched
- Published
CVE-2026-82383 is a missing authentication for critical function vulnerability in Apache Roller 6.1.5. An unauthenticated remote attacker can access a configuration endpoint that should require admin credentials and persistently change a site-global configuration value, specifically the frontpage weblog selection.
What to do: Upgrade Apache Roller to a patched version. See the NVD record and the Apache Roller GitHub fix.
