CVE-2026-86507: XSS via Comment-Author URL in Apache Roller 6.1.5
CVE-2026-86507 Published on September 28, 2026
Apache Roller: Stored XSS in comment moderation via comment author URL
Improper neutralization of input in Apache Roller 6.1.5 allows an anonymous remote attacker to store a crafted comment-author URL that can execute script in the session of a weblog moderator or global administrator when the comment management page is viewed. This affects sites that permit comments on at least one weblog and whose moderator subsequently reviews the submitted comment; no non-default server setting is required. Users are recommended to upgrade to Apache Roller 6.1.6 or later.
Vulnerability Analysis
CVE-2026-86507 can be exploited with network access, requires user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality and integrity, and no impact on availability.
Weakness Type
What is a XSS Vulnerability?
The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVE-2026-86507 has been classified to as a XSS vulnerability or weakness.
Products Associated with CVE-2026-86507
Want to know whenever a new CVE is published for Apache Roller? stack.watch will email you.