Sceawere

Vulnerability Detail

CVE-2026-82375UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Apache Roller SSRF Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.4
Creation Date
4h ago
Vendor
Apache Software Foundation
Product
Apache Roller
Attack Type
CWE-918: Server-Side Request Forgery (SSRF)
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Server-Side Request Forgery (SSRF) in Apache Roller 6.1.5 allows an authenticated user with entry-editing rights on a weblog to cause outbound HTTP requests to attacker-chosen destinations through legacy outbound Trackback and entry enclosure handling. The Trackback control is hidden in the standard UI, but its action remains directly reachable; the enclosure path is relevant only when an author supplies an enclosure URL. No non-default server configuration is required, and the default empty Trackback allow-list permits all destinations. Requests can reach loopback and private-network addresses, while enclosure handling exposes response status, content type, and length. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which removes the outbound trackback action and stops dereferencing enclosure URLs.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.4",
  "pubDate": "2026-09-28T08:16:41.170Z",
  "pubdate": "2026-09-28T08:16:41.170Z",
  "executiveSummary": "A Server-Side Request Forgery (SSRF) vulnerability exists in Apache Roller 6.1.5, allowing authenticated users with weblog entry-editing privileges to initiate unauthorized outbound HTTP requests.\nThis vulnerability stems from legacy functionality within the Trackback and entry enclosure handling mechanisms. Although the Trackback user interface is obscured, the underlying server-side actions remain active and accessible.\nThe default configuration lacks restrictions on destination endpoints, permitting requests to arbitrary URLs, including sensitive loopback (127.0.0.1) and private-network (RFC 1918) addresses.\nAn attacker can leverage this to perform internal network reconnaissance, interact with local services, or bypass firewall protections.\nFurthermore, the enclosure handling mechanism facilitates information disclosure by returning specific response metadata, such as HTTP status codes, Content-Type headers, and response length, to the requester.\nThe vulnerability is exploitable by an authenticated user with standard entry-editing rights without requiring non-default server configurations. Impact includes the potential for internal service probing and unauthorized resource access within the server's network environment.",
  "technicalDetails": "The vulnerability is located in the legacy Trackback and entry enclosure components of Apache Roller 6.1.5. The primary root cause is the server-side processing of user-supplied URLs without appropriate validation or network-level filtering, combined with a default-permissive allow-list policy.\nThe attack flow initiates when an authenticated user, possessing sufficient privileges for weblog entry management, interacts with the legacy Trackback functionality. Although the UI components for Trackbacks are hidden, the server-side action endpoints remain reachable via direct HTTP requests. By submitting an arbitrary target URL to these endpoints, the application acts as a proxy, executing outbound HTTP requests on behalf of the attacker.\nIn the context of enclosure handling, the vulnerability is triggered when an author submits a malicious enclosure URL. The application attempts to resolve and dereference this URL to retrieve metadata. Because the application does not validate the target destination, it can be coerced into reaching internal network segments. By observing the responses provided by the server—specifically the HTTP response status, Content-Type, and length—the attacker can perform reconnaissance on internal systems that are otherwise inaccessible from the public Internet.\nThis SSRF vector allows an attacker to interact with the loopback interface (localhost) to exploit non-public services or communicate with internal APIs and administrative panels on the local network. The lack of an enforced, restrictive allow-list for outbound requests exacerbates the risk, ensuring that requests to private-network addresses are successfully routed by the application server.\nThe authentication requirement is limited to possessing entry-editing rights, which is a common privilege level for contributors within the Apache Roller ecosystem. The attack does not require any specialized server configuration, as the default state of the application is vulnerable. Post-exploitation impact ranges from internal network mapping and service enumeration to the potential for further exploitation of internal services that trust requests originating from the application server."
}
CVE-2026-82375: Apache Roller SSRF Vulnerability (HIGH Severity, CVSS: 7.4) | Sceawere