OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-82386

HIGH · CVSS 7.7 EPSS 0.29% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-28 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

Apache Roller 6.1.5 is vulnerable due to improper handling of XML External Entity (XXE) references, allowing weblog administrators to read sensitive files and access internal network addresses via a specially crafted OPML document. This vulnerability does not require any non-default configurations, making it critical for all users of the affected version to prioritize upgrading to Apache Roller 6.1.6 or later, which addresses the issue by implementing a hardened parser that disables external entity resolution. Organizations using Apache Roller should take immediate action to mitigate potential data exposure and network access risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-82386
Severity
HIGH
CVSS
7.7
EPSS
0.29%
Apache

Original NVD Description

Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a weblog administrator to read files readable by the Roller process and reach internal network addresses by importing a crafted OPML document, because the bookmark import parser does not disable external entity resolution. No non-default configuration is required; the import is reached through the administrator bookmark-import action. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which uses a hardened parser that disables external entities and document type declarations.