An alert published on September 25, 2026, reports that Apache Roller 6.1.5 accepts requests without the required salt token, enabling actions on behalf of logged-in users.
The alert for CVE-2026-82380 reports a cross-site request forgery (CSRF) flaw in Apache Roller 6.1.5. Its filters accept requests that omit the required salt token and validate the request by another means. As a result, a remote attacker may induce a logged-in user to perform state-changing actions under that user's authority. Version 6.1.5 is the affected version listed.
Published on September 25, 2026, the alert rates severity as important and gives a CVSS 3.1 score of 8.1, high, with vector AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H. The available text is an automated translation of a post in the oss-sec feed and ends mid-description. Consult the original post in the feed archive to check the full content and any updates; also confirm the installed version and system status using official project sources.