---
id: CVE-2026-86507
title: >-
  Improper neutralization of input in Apache Roller 6.1.5 allows an anonymous
  remote attacker to store a crafted comment-author URL that can execute script
  in the session of a weblog moderator or global administrator when the comment
  manag…
summary: >-
  Improper neutralization of input in Apache Roller 6.1.5 allows an anonymous
  remote attacker to store a crafted comment-author URL that can execute script
  in the session of a weblog moderator or global administrator when the comment
  manag…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: Apache Software Foundation
product: Apache Roller
affected:
  - apache_roller 6.1.5
published: '2026-09-28'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T10:16:45.883'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86507'
references:
  - url: 'https://github.com/apache/roller/pull/181'
    label: security@apache.org
  - url: 'https://lists.apache.org/thread/rjyxvm0fgtdfxwkj5qv532htdbs05wff'
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2026/09/25/22'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-28T09:06:28.558Z'
---

## Overview

Improper neutralization of input in Apache Roller 6.1.5 allows an anonymous remote attacker to store a crafted comment-author URL that can execute script in the session of a weblog moderator or global administrator when the comment management page is viewed. This affects sites that permit comments on at least one weblog and whose moderator subsequently reviews the submitted comment; no non-default server setting is required. Users are recommended to upgrade to Apache Roller 6.1.6 or later.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
