Sceawere

Vulnerability Detail

CVE-2026-82377UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Apache Roller Broken Access Control

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.9
Creation Date
4h ago
Vendor
Apache Software Foundation
Product
Apache Roller
Attack Type
CWE-862: Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Missing Authorization in Apache Roller 6.1.5 allows an authenticated user to read, modify, or delete weblog content belonging to other weblogs through the legacy XML-RPC Blogger and MetaWeblog APIs, because the handlers authenticate the caller but do not verify the caller's permission on the weblog or entry actually affected. Only installations that enable the non-default global XML-RPC setting are affected; the per-weblog API flag defaults to enabled for UI-created weblogs. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which applies an explicit per-method permission check, or to keep the XML-RPC feature disabled.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.9",
  "pubDate": "2026-09-28T08:16:41.417Z",
  "pubdate": "2026-09-28T08:16:41.417Z",
  "executiveSummary": "This vulnerability involves a critical Missing Authorization flaw within Apache Roller 6.1.5, specifically impacting the legacy XML-RPC Blogger and MetaWeblog API handlers. The flaw allows an authenticated user to perform unauthorized read, modification, or deletion operations on weblog content belonging to other users. The vulnerability arises from an architectural oversight where the API handlers perform authentication but fail to implement subsequent authorization checks to ensure the caller has adequate permissions for the specific weblog or entry being targeted.\nThe risk is significant for deployments where the non-default global XML-RPC feature is enabled, as the per-weblog API flag defaults to 'enabled' for UI-created weblogs. An attacker with a valid account can exploit this to bypass data ownership constraints, resulting in unauthorized data access or malicious content manipulation. While the attack requires a valid user account, the lack of object-level authorization permits horizontal and vertical privilege escalation regarding content management. Mitigation requires upgrading to version 6.1.6 or disabling the vulnerable XML-RPC interface.",
  "technicalDetails": "The root cause of this vulnerability is a Broken Access Control (BAC) implementation in the Apache Roller 6.1.5 XML-RPC service. The vulnerability manifests within the handlers responsible for processing Blogger and MetaWeblog API requests. While the system correctly invokes authentication routines to verify the identity of the incoming request's principal, it fails to perform an authorization check against the requested resource.\nSpecifically, the API handlers lack an explicit permission validation step to verify if the authenticated user possesses the 'AUTHOR' or 'ADMIN' role associated with the specific 'weblog' or 'entry' resource identified in the XML-RPC payload. Because the application logic trusts the request parameters without validating the relationship between the authenticated user and the target resource, it allows any authenticated user to pass arbitrary identifiers to the API methods.\nThe exploitation flow proceeds as follows: First, an authenticated attacker crafts an XML-RPC request targeting the Blogger or MetaWeblog API endpoints. The attacker includes the identifiers (e.g., blog IDs or post IDs) of a target weblog they do not own. Because the service successfully authenticates the user, it proceeds to process the request context. Since the backend handler lacks a per-method authorization check, it performs the requested operation—such as 'editPost', 'deletePost', or 'getRecentPosts'—on the target resource specified by the attacker, effectively ignoring the boundaries of content ownership.\nThis vulnerability is restricted to installations where the global XML-RPC configuration is enabled. In many instances, the default state of the per-weblog API flag for UI-created weblogs is 'enabled', which broadens the attack surface for existing content. The impact is significant, as it enables an attacker to perform unauthorized CRUD operations on weblog content, leading to data loss, modification of public-facing web content, or the extraction of sensitive information stored in draft or private posts. The fix introduced in version 6.1.6 addresses this by implementing an explicit per-method permission check that mandates verification of user permissions relative to the specific resource involved in the XML-RPC operation."
}
CVE-2026-82377: Apache Roller Broken Access Control (CRITICAL Severity, CVSS: 9.9) | Sceawere