天下漏洞,尽知其名
CRITICAL

CVE-2026-82377 Apache Roller 授权缺失漏洞

影响已认证用户可越权读取、修改或删除他人博客内容

AI 研判

Apache Roller 6.1.5 的旧版 XML-RPC Blogger 与 MetaWeblog API 处理器存在授权缺失问题。处理器仅验证调用者身份,却未校验其对目标博客或条目的操作权限,导致已认证用户可越权访问他人博客内容。该漏洞 CVSS 评分 9.9,属严重级别。

影响范围

Apache Roller

Apache Roller 6.1.5。仅当启用非默认的全局 XML-RPC 设置时受影响;UI 创建的博客其单博客 API 标志默认启用。

漏洞详情

漏洞类型为授权缺失(Missing Authorization)。XML-RPC 接口在处理请求时只确认调用者已登录,未检查其是否拥有对所操作博客或条目的权限,从而形成越权。攻击者可借助 Blogger 或 MetaWeblog 接口对他人博客内容进行读取、修改或删除。

利用条件与风险

利用前提是目标安装启用了全局 XML-RPC 功能,且攻击者拥有一个已认证账户。由于单博客 API 标志默认开启,实际暴露面可能较大,越权操作可造成数据泄露与内容篡改。

修复建议

官方建议升级至 Apache Roller 6.1.6 或更高版本,该版本增加了逐方法的显式权限检查;临时缓解措施为保持 XML-RPC 功能处于禁用状态。

原始情报

Missing Authorization in Apache Roller 6.1.5 allows an authenticated user to read, modify, or delete weblog content belonging to other weblogs through the legacy XML-RPC Blogger and MetaWeblog APIs, because the handlers authenticate the caller but do not verify the caller’s permission on the weblog or entry actually affected. Only installations that enable the non-default global XML-RPC setting are affected; the per-weblog API flag defaults to enabled for UI-created weblogs. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which applies an explicit per-method permission check, or to keep the XML-RPC feature disabled.