Skip to content
Rota Nacional

Cyber ·

CVE-2026-82386: Apache Roller OPML import flaw

A notice published on September 25, 2026 reports a vulnerability in Apache Roller 6.1.5: an administrator could exploit OPML import to read files accessible to the process and reach internal network addresses.

A security notice about CVE-2026-82386 describes a flaw in Apache Roller 6.1.5. Classified as important, the vulnerability received a CVSS 3.1 score of 7.7 (high), with vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N. The record was published on September 25, 2026, and attributes the issue to XML external entity handling during OPML bookmark import.

According to the text, a weblog administrator could import a crafted OPML document to read files accessible to the Roller process and reach internal network addresses. The stated cause is that the import parser does not disable external entities. To confirm the scope and track any updates, consult the original notice in the oss-sec mailing list archive and compare it with official Apache Roller project advisories; do not assume from this report alone that a fixed version is available.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free