Skip to content
Rota Nacional

Cyber ·

CVE-2026-82380: CSRF flaw in Apache Roller

An alert published on September 25, 2026, reports that Apache Roller 6.1.5 accepts requests without the required salt token, enabling actions on behalf of logged-in users.

The alert for CVE-2026-82380 reports a cross-site request forgery (CSRF) flaw in Apache Roller 6.1.5. Its filters accept requests that omit the required salt token and validate the request by another means. As a result, a remote attacker may induce a logged-in user to perform state-changing actions under that user's authority. Version 6.1.5 is the affected version listed.

Published on September 25, 2026, the alert rates severity as important and gives a CVSS 3.1 score of 8.1, high, with vector AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H. The available text is an automated translation of a post in the oss-sec feed and ends mid-description. Consult the original post in the feed archive to check the full content and any updates; also confirm the installed version and system status using official project sources.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free