Sceawere
Vulnerability Detail
CVE-2026-82380UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Apache Roller CSRF Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.1
- Creation Date
- 4h ago
- Vendor
- Apache Software Foundation
- Product
- Apache Roller
- Attack Type
- CWE-352: Cross-Site Request Forgery (CSRF)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Cross-Site Request Forgery (CSRF) in Apache Roller 6.1.5 allows a remote attacker to cause a logged-in user to perform state-changing actions under the victim's authority, because the CSRF validation filters accept a request that does not submit the required salt token, validating instead against a value the server itself generated for the request. No optional feature or non-default configuration is required; any logged-in author or administrator is affected when induced to visit a crafted page. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which validates only the submitted salt and applies the same check to multipart forms.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.1",
"pubDate": "2026-09-28T08:16:41.787Z",
"pubdate": "2026-09-28T08:16:41.787Z",
"executiveSummary": "This vulnerability is a Cross-Site Request Forgery (CSRF) flaw within Apache Roller version 6.1.5, which allows remote, unauthenticated attackers to perform unauthorized state-changing actions on behalf of authenticated users.\nThe security defect stems from improper validation of anti-CSRF tokens, where the server-side logic inadvertently falls back to validating against internally generated values rather than strictly enforcing the presence and correctness of a user-submitted salt token.\nThe flaw affects any logged-in author or administrator, regardless of configuration, as no non-default settings or specific features are required to exploit the application.\nAn attacker can exploit this by inducing an authenticated user to visit a malicious, crafted webpage, triggering unauthorized operations within the victim's session context.\nThis could result in unauthorized administrative modifications, account configuration changes, or the execution of privileged functions without the user's consent or knowledge.\nThe inherent risk is high, as it bypasses authorization controls by leveraging existing session persistence, necessitating an immediate upgrade to the patched version.",
"technicalDetails": "The vulnerability resides within the CSRF validation filter logic of Apache Roller 6.1.5. In a typical secure implementation, CSRF protection relies on a unique, unpredictable 'salt' or 'token' generated by the server and included as a hidden field in state-changing requests. The server validates the request by comparing the submitted token against the expected token associated with the user's session.\nIn the vulnerable implementation, the validation mechanism exhibits a failure in its conditional logic. When a request is received that lacks the necessary anti-CSRF salt token, the filter fails to reject the request outright. Instead, the application erroneously defaults to validating the request against a value generated internally by the server for that specific request context. This behavior effectively nullifies the purpose of the anti-CSRF token, as the server treats the absence of a client-provided token as a valid state if the internal logic provides a fallback match.\nThe attack flow proceeds as follows: First, an attacker constructs a malicious webpage containing a hidden form or a scripted request targeting an administrative or state-changing endpoint within the Apache Roller instance (e.g., /roller-ui/authoring/...). Second, the attacker induces an authenticated victim—such as an administrator or blog author—to navigate to the crafted URL while their Apache Roller session is active. Third, the browser automatically attaches the victim's session cookies to the forged request. Finally, when the request reaches the server, the faulty CSRF filter fails to enforce the presence of a legitimate salt token and permits the execution of the state-changing operation under the victim's authority.\nThis vulnerability also extends to multipart form submissions, where the same weak validation logic is applied. Because the server does not enforce strict token verification, the system becomes vulnerable to forced administrative actions, such as changing system settings, modifying existing blog content, or updating user profile information. The impact is significant because the attacker does not need to know the CSRF token; they only need to bypass the filter's lax validation routine. All versions prior to 6.1.6 are susceptible to this vector, as the flaw resides in the core architectural handling of request authentication tokens within the application's filtering stack."
}