Project Roller
Blogs, news and views
Blog Better! Roller is the open source Java blog server that drives Apache Software Foundation blogs and others. Read more on the about page.
Quick Links
Navigation
Apache Roller 6.1.6 fixes 18 security vulnerabilities
09.27.2026 by Dave Johnson | 0 Comments
Apache Roller 6.1.6 fixes 18 security vulnerabilities. Apache Roller 6.1.5 is affected. Upgrade to 6.1.6 now.
Every installation should upgrade. Some vulnerabilities need no optional feature. Vulnerabilities were found in these features:
- Comments & Trackbacks, LDAP comment authentication
- Multiple users and weblogs
- Media file uploads
- The frontpage theme
- XML-RPC (MetaWeblog or Blogger API), even when disabled
- AtomPub with WSSE authentication
- OAuth
Each CVE links to its advisory.
Critical
- CVE-2026-82384: Unauthenticated XML-RPC deserialization
Important
- CVE-2026-82348: Cross-weblog resource tampering
- CVE-2026-82376: XXE in trackback parser
- CVE-2026-82380: CSRF protection bypass
- CVE-2026-82381: Stored XSS in authoring UI
- CVE-2026-82383: Anonymous setup tampering
- CVE-2026-82385: Velocity template sandbox escape
- CVE-2026-82386: XXE in OPML import
- CVE-2026-86507: Stored XSS in comment moderation
Moderate
- CVE-2026-82375: SSRF via trackback and enclosure
- CVE-2026-82377: Missing XML-RPC weblog authorization
- CVE-2026-82378: OAuth endpoint trusts request identity
- CVE-2026-82379: WSSE authentication replay
- CVE-2026-82382: Reflected XSS in frontpage
- CVE-2026-82387: Stored XSS via media type
- CVE-2026-82546: Stored XSS via trackback links
- CVE-2026-91204: Stored javascript: URI in comments
- CVE-2026-91206: Reflected XSS in LDAP authenticator
Some changes affect existing installations. Read the release notes before you upgrade.
Thanks to the reporters and to everyone who reviewed and tested the fixes.