---
id: CVE-2026-82348
title: >-
  Authorization Bypass Through User-Controlled Key in Apache Roller 6.1.5 allows
  an authenticated user with authoring rights on one weblog to read, modify, or
  delete resources belonging to another weblog through unscoped identifier-based
  l…
summary: >-
  Authorization Bypass Through User-Controlled Key in Apache Roller 6.1.5 allows
  an authenticated user with authoring rights on one weblog to read, modify, or
  delete resources belonging to another weblog through unscoped identifier-based
  l…
severity: high
cvss: 7.7
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:L'
cwe:
  - CWE-639
vendor: Apache Software Foundation
product: Apache Roller
affected:
  - apache_roller 6.1.5
published: '2026-09-28'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T09:17:05.683'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82348'
references:
  - url: 'https://github.com/apache/roller/pull/162'
    label: security@apache.org
  - url: 'https://lists.apache.org/thread/3h7zk8dhbt8fj5zdt8cjghx0b807wgy1'
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2026/09/25/7'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-28T08:05:44.640Z'
---

## Overview

Authorization Bypass Through User-Controlled Key in Apache Roller 6.1.5 allows an authenticated user with authoring rights on one weblog to read, modify, or delete resources belonging to another weblog through unscoped identifier-based lookups. This affects multi-user installations where users are intended to be isolated between weblogs; no optional feature or non-default configuration is required. A user with administrator rights on their weblog can also overwrite another weblog's Velocity template, whose content is evaluated when the victim weblog renders. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which scopes authoring resource lookups to the acting weblog.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
