CVE WATCH / VULNERABILITY DETAIL

CVE-2026-82377

CRITICALCVSS 9.9NVD feed

Published 28 September 2026 · tracked since 28 September 2026

Description

Missing Authorization in Apache Roller 6.1.5 allows an authenticated user to read, modify, or delete weblog content belonging to other weblogs through the legacy XML-RPC Blogger and MetaWeblog APIs, because the handlers authenticate the caller but do not verify the caller's permission on the weblog

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-82377 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-82377

CRITICALCVSS 9.9NVD feed

Published 28 September 2026 · tracked since 28 September 2026

Description

Missing Authorization in Apache Roller 6.1.5 allows an authenticated user to read, modify, or delete weblog content belonging to other weblogs through the legacy XML-RPC Blogger and MetaWeblog APIs, because the handlers authenticate the caller but do not verify the caller's permission on the weblog

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]