Skip to content
Rota Nacional

Cyber ·

CVE-2026-82387: Stored XSS in Apache Roller

A notice published on September 25, 2026 reports stored XSS in Apache Roller 6.1.5: users permitted to upload media may store active content because the system trusts the content type supplied with the upload.

A security notice published on September 25, 2026 describes CVE-2026-82387 in Apache Roller 6.1.5. The flaw is classified as stored XSS: a user permitted to upload media can store active content at the Roller origin because the upload feature trusts the content type supplied with the upload.

The notice gives the issue moderate severity and a CVSS 3.1 score of 5.4. Its published vector is AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N. The affected version listed is Apache Roller 6.1.5. The available text does not specify a fix or other affected versions.

To assess exposure, check whether your organization uses the listed version and which accounts can upload media. Consult the original notice in the oss-sec feed and Apache Roller’s official security information; confirm the version, score, and update guidance before taking action. Do not assume the translated description includes every detail.

When using AI to summarize or apply the notice, submit only necessary excerpts and remove names, email addresses, internal addresses, and other identifying data. Verify technical recommendations against official sources: automated analysis does not replace review by the responsible team.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free