Sceawere

Vulnerability Detail

CVE-2026-82387UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Apache Roller Stored XSS Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.4
Creation Date
4h ago
Vendor
Apache Software Foundation
Product
Apache Roller
Attack Type
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a user with media-upload rights to store active content on Roller's origin, because the media upload feature trusts the upload-supplied content type and serves the stored file back with that type. A victim who opens the uploaded file executes the stored script. Media uploads are disabled by default; only installations that enable them are affected, and the shipped type restrictions do not block active content once uploads are on. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which derives the stored type from file content and serves non-image media as a download.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.4",
  "pubDate": "2026-09-28T08:16:42.647Z",
  "pubdate": "2026-09-28T08:16:42.647Z",
  "executiveSummary": "Apache Roller 6.1.5 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability originating from insecure media file handling. This vulnerability is classified as CWE-79: Improper Neutralization of Input During Web Page Generation.\nThe flaw exists within the media upload feature, where the system relies exclusively on the user-provided Content-Type header when storing and serving uploaded files. This trust in client-supplied metadata allows authenticated users with media-upload privileges to upload malicious files containing active scripts.\nWhen a victim accesses the stored file, the browser interprets the script based on the attacker-controlled Content-Type, leading to code execution within the victim's session on the Apache Roller origin. While media uploads are disabled by default, environments that have enabled this feature are at significant risk. The exploitation allows attackers to perform unauthorized actions, hijack sessions, or exfiltrate sensitive data. Immediate remediation through upgrading to version 6.1.6 or later is required to enforce robust file type validation based on content inspection rather than user-provided headers.",
  "technicalDetails": "The root cause of this vulnerability lies in an improper input validation mechanism within the Apache Roller 6.1.5 media management subsystem. The application fails to perform deep content inspection on uploaded binary objects, relying instead on the Content-Type header provided by the client during the POST request. By spoofing the Content-Type to match an executable format (e.g., text/html) while uploading a file containing malicious JavaScript payloads, an attacker can bypass existing extension-based restrictions.\nThe exploitation flow is as follows: First, an attacker with valid media-upload permissions navigates to the media management interface. Second, the attacker uploads a file, such as an HTML document containing arbitrary script tags, while manipulating the upload request headers to misrepresent the file type as a standard image or benign media type. Third, Apache Roller stores the file on the server's origin. Finally, when a target user or administrator views or downloads the file via the Roller origin, the server serves the malicious content using the attacker-supplied Content-Type header. Consequently, the victim's browser executes the embedded script in the context of the Apache Roller web application.\nThis vulnerability is strictly an authenticated attack vector, requiring the attacker to possess sufficient privileges to perform media uploads. Because the application explicitly trusts the upload-supplied MIME type, it bypasses the security logic that is intended to prevent the hosting of active web content. The payload behavior is limited only by the attacker's ability to craft JavaScript that interacts with the browser's Document Object Model (DOM) of the Roller site. Post-exploitation impact includes the potential for session hijacking through credential theft, the execution of unauthorized administrative operations, or the delivery of further malicious payloads to other authenticated users interacting with the platform.\nThe vulnerability affects Apache Roller 6.1.5. Installations that have not enabled media uploads remain unaffected by this specific vector. The remediation logic introduced in Apache Roller 6.1.6 shifts the security model from trust-on-input to a server-side validation model. Specifically, the updated version derives the content type directly from the file's binary signature (magic numbers) and forces a download disposition for non-image media types, thereby preventing browsers from executing stored scripts as web pages."
}
CVE-2026-82387: Apache Roller Stored XSS Vulnerability (MEDIUM Severity, CVSS: 5.4) | Sceawere