Apache Roller 6.1.5: stored XSS in comment moderation
A security bulletin published on September 25, 2026, reports a stored XSS flaw in Apache Roller 6.1.5, triggered when a moderator or administrator views the comment moderation page.
The bulletin assigns CVE-2026-86507 to an input-validation flaw in Apache Roller 6.1.5. A remote, anonymous attacker could store a crafted comment-author URL; if a weblog moderator or global administrator viewed the comment management page, a script could run in that person’s session. The notice rates the severity as important and gives a CVSS 3.1 score of 6.1, with vector AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N. The affected version listed is 6.1.5.
The item, dated September 25, 2026, is an automatic translation of content from the oss-sec feed and attributes the notice to David M. Johnson. The supplied excerpt ends before completing its information about which sites are affected. To verify details, locate the original post in the oss-sec archive, check the Apache Roller project notice, and compare the version, vector, and scope; do not assume the incomplete excerpt explains exposure conditions. If using AI to analyze the notice or prepare a response, remove personal data and internal information before submission and follow your organization’s policy.