CVE-2026-82376
HIGH
7,7
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: changed
Confidentiality: high
Integrity: none
Availability: none
Description
AI Translation Available
Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a user with entry-editing rights on a weblog to cause the server to parse an attacker-influenced trackback response with an XML parser that does not disable external entity resolution, leading to disclosure of files readable by the Roller process. The Trackback control is hidden in the standard UI, but its action remains directly reachable, and no non-default server configuration is required. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which removes the outbound trackback response parser.
611
Improper Restriction of XML External Entity Reference
DraftCommon Consequences
Security Scopes Affected:
Confidentiality
Integrity
Availability
Potential Impacts:
Read Application Data
Read Files Or Directories
Bypass Protection Mechanism
Dos: Resource Consumption (Cpu)
Dos: Resource Consumption (Memory)
Applicable Platforms
Languages:
Not Language-Specific, XML
Technologies:
Not Technology-Specific, Web Based
http://www.openwall.com/lists/oss-security/2026/09/25/9
https://github.com/apache/roller/pull/163
https://lists.apache.org/thread/dxqmd3873q87h06xpjjc9lnvp4jblz0l