A bulletin published on September 25, 2026 reports reflected XSS in Apache Roller 6.1.5, involving a manipulated directory parameter.
The bulletin for CVE-2026-82382 describes a reflected cross-site scripting (XSS) flaw in Apache Roller 6.1.5. According to the report, a remote attacker can supply a manipulated blog directory parameter and target visitors of weblogs using the included front-page theme. The publication rates the severity as moderate: CVSS 3.1 score 6.1, with vector AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N. The listed affected version is 6.1.5.
Published on September 25, 2026, the notice is presented as an automatic translation of material from the oss-sec feed. To confirm its context, wording, and any updates, consult the original publication in the feed archive and compare it with Apache Roller advisories and the CVE record. If using an AI tool to analyze the bulletin or apply it to your organization’s environment, do not submit logs, user data, or identifiable internal details; use sanitized excerpts.