天下漏洞,尽知其名
HIGH 重点关注

CVE-2026-82348 Apache Roller 授权绕过漏洞

影响越权读写删其他博客资源,并可注入模板执行代码

AI 研判

Apache Roller 6.1.5 存在授权绕过漏洞(CVE-2026-82348,CVSS 7.7)。拥有某个博客作者权限的已认证用户,可通过未限定作用域的标识符查询,读取、修改或删除其他博客的资源。在多用户隔离部署中,攻击者还可覆盖他人博客的 Velocity 模板,从而在受害者博客渲染时执行模板内容。

影响范围

Apache Roller

Apache Roller 6.1.5;官方建议升级至 6.1.6 或更高版本。其他版本是否受影响暂无公开信息。

漏洞详情

漏洞属于通过用户可控键值导致的授权绕过(IDOR 类)。系统在按标识符查找博客资源时未将查询范围限定在当前操作的博客内,导致已认证用户可越权访问其他博客的对象。若攻击者在其自身博客拥有管理员权限,还能覆盖其他博客的 Velocity 模板,而模板内容会在受害者博客渲染时被求值,可能升级为代码执行。

利用条件与风险

利用需先拥有一个博客的作者权限并通过认证,无需非默认配置或可选功能,多用户实例风险较高;模板覆盖可导致远程代码执行。

修复建议

升级至 Apache Roller 6.1.6 或更高版本,该版本将作者资源查询限定在操作所属博客内。临时缓解措施暂无公开信息。

原始情报

Authorization Bypass Through User-Controlled Key in Apache Roller 6.1.5 allows an authenticated user with authoring rights on one weblog to read, modify, or delete resources belonging to another weblog through unscoped identifier-based lookups. This affects multi-user installations where users are intended to be isolated between weblogs; no optional feature or non-default configuration is required. A user with administrator rights on their weblog can also overwrite another weblog’s Velocity template, whose content is evaluated when the victim weblog renders. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which scopes authoring resource lookups to the acting weblog.