A September 25, 2026 advisory reports a moderate reflected XSS issue in Apache Roller 6.1.5’s optional LDAP comment authenticator.
A security advisory published on September 25, 2026 describes CVE-2026-91206 in Apache Roller 6.1.5. The issue is classified as reflected XSS in the optional LDAP comment authenticator: request parameter values are written into its HTML form without adequate sanitization. The advisory rates it moderate, with CVSS 3.1 score 6.1, and lists user interaction as required; it reports potential confidentiality and integrity impact, with no availability impact. The listed affected version is 6.1.5.
The report was posted by David M. Johnson to the oss-sec mailing list. Consult the original advisory to confirm details, context, and any updates; the available description ends before completing the technical explanation. Organizations using the listed version should check the advisory and official project notices before choosing a response. If using AI tools to study the material, avoid submitting logs, user data, or identifiable internal details; use sanitized examples and follow organizational data policies.