Skip to content
Rota Nacional

Cyber ·

Apache Roller 6.1.5: Trackback-stored XSS alert

A notice published on September 25, 2026 describes stored XSS in Apache Roller 6.1.5. The risk depends on published entries accepting comments and Trackbacks; the stated severity is moderate, with a CVSS 3.1 score of 6.1.

The notice for CVE-2026-82546 reports that Apache Roller 6.1.5 allows a crafted comment-author URL to be stored through the received Trackback endpoint. According to the description, this can lead to script execution on pages when a published entry accepts comments and Trackbacks. The attack is remote and requires no authentication; the stated CVSS 3.1 score is 6.1, medium severity. The feed publication is dated September 25, 2026.

The stated scope is Roller 6.1.5, and the text does not specify a fix or other affected versions. Consult the original notice cited by the oss-sec feed, and check Apache Roller project documentation and announcements to confirm impact and remediation status before acting. If you use AI to analyze the notice or prepare a response, avoid submitting internal data, credentials, or personal information; apply your organization’s policy and check the analysis against the original sources.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free