OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-82376

HIGH · CVSS 7.7 EPSS 0.30% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-28 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

Apache Roller versions prior to 6.1.6 are vulnerable to improper restriction of XML External Entity (XXE) references, allowing users with entry-editing rights to exploit the trackback feature and potentially disclose sensitive files on the server. This vulnerability poses a significant risk, as it can lead to unauthorized access to files readable by the Roller process without requiring any non-default configurations. Organizations using affected versions should prioritize upgrading to 6.1.6 or later to mitigate this high-severity risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-82376
Severity
HIGH
CVSS
7.7
EPSS
0.30%
Apache

Original NVD Description

Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a user with entry-editing rights on a weblog to cause the server to parse an attacker-influenced trackback response with an XML parser that does not disable external entity resolution, leading to disclosure of files readable by the Roller process. The Trackback control is hidden in the standard UI, but its action remains directly reachable, and no non-default server configuration is required. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which removes the outbound trackback response parser.