---
id: CVE-2026-82376
title: >-
  Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5
  allows a user with entry-editing rights on a weblog to cause the server to
  parse an attacker-influenced trackback response with an XML parser that does
  not disa…
summary: >-
  Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5
  allows a user with entry-editing rights on a weblog to cause the server to
  parse an attacker-influenced trackback response with an XML parser that does
  not disa…
severity: high
cvss: 7.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'
cwe:
  - CWE-611
vendor: Apache Software Foundation
product: Apache Roller
affected:
  - apache_roller 6.1.5
published: '2026-09-28'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T09:17:05.883'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82376'
references:
  - url: 'https://github.com/apache/roller/pull/163'
    label: security@apache.org
  - url: 'https://lists.apache.org/thread/dxqmd3873q87h06xpjjc9lnvp4jblz0l'
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2026/09/25/9'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-28T08:05:44.636Z'
---

## Overview

Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a user with entry-editing rights on a weblog to cause the server to parse an attacker-influenced trackback response with an XML parser that does not disable external entity resolution, leading to disclosure of files readable by the Roller process. The Trackback control is hidden in the standard UI, but its action remains directly reachable, and no non-default server configuration is required. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which removes the outbound trackback response parser.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
