CVE-2026-82376
7.7 HIGHpublic exploit availablePublished 2026-09-28 · Updated 2026-09-28
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a user with entry-editing rights on a weblog to cause the server to parse an attacker-influenced trackback response with an XML parser that does not disable external entity resolution, leading to disclosure of files readable by the Roller process. The Trackback control is hidden in the standard UI, but its action remains directly reachable, and no non-default server configuration is required. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which removes the outbound trackback response parser.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Weaknesses
CWE-611
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-10025
- MEDIUMCVE-2026-14304PoC
- HIGHCVE-2026-17646
- HIGHCVE-2026-18172
- HIGHCVE-2026-18184
- HIGHCVE-2026-61570PoC
- CRITICALCVE-2026-61741PoC
- HIGHCVE-2026-81536
Related by shared AI tags and CWE weakness class. Browse the full archive.