A notice published on September 25, 2026 describes stored XSS in Apache Roller 6.1.5. The risk depends on published entries accepting comments and Trackbacks; the stated severity is moderate, with a CVSS 3.1 score of 6.1.
The notice for CVE-2026-82546 reports that Apache Roller 6.1.5 allows a crafted comment-author URL to be stored through the received Trackback endpoint. According to the description, this can lead to script execution on pages when a published entry accepts comments and Trackbacks. The attack is remote and requires no authentication; the stated CVSS 3.1 score is 6.1, medium severity. The feed publication is dated September 25, 2026.
The stated scope is Roller 6.1.5, and the text does not specify a fix or other affected versions. Consult the original notice cited by the oss-sec feed, and check Apache Roller project documentation and announcements to confirm impact and remediation status before acting. If you use AI to analyze the notice or prepare a response, avoid submitting internal data, credentials, or personal information; apply your organization’s policy and check the analysis against the original sources.