XXE via Trackback Parser in Apache Roller 6.1.5
CVE-2026-82376 Published on September 28, 2026
Apache Roller: XML external entity processing in trackback response parser
Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a user with entry-editing rights on a weblog to cause the server to parse an attacker-influenced trackback response with an XML parser that does not disable external entity resolution, leading to disclosure of files readable by the Roller process. The Trackback control is hidden in the standard UI, but its action remains directly reachable, and no non-default server configuration is required. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which removes the outbound trackback response parser.
Vulnerability Analysis
CVE-2026-82376 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity and availability.
Weakness Type
What is a XXE Vulnerability?
The software processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
CVE-2026-82376 has been classified to as a XXE vulnerability or weakness.
Products Associated with CVE-2026-82376
Want to know whenever a new CVE is published for Apache Roller? stack.watch will email you.