PatchSiren cyber security CVE debrief
CVE-2026-91204 Apache Software Foundation CVE debrief
CVE-2026-91204 is a Cross-site Scripting (XSS) vulnerability in Apache Roller 6.1.5. An anonymous remote attacker can store a comment with a javascript: URI link that executes script in the browser of a visitor who clicks it, affecting sites with HTML comments enabled and the HTMLSubset comment formatter. Users should upgrade to Apache Roller 6.1.6 or later.
- Vendor
- Apache Software Foundation
- Product
- Apache Roller
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-28
- Original CVE updated
- 2026-09-28
- Advisory published
- 2026-09-28
- Advisory updated
- 2026-09-28
Who should care
Defenders of Apache Roller sites, particularly those with HTML comments enabled and the HTMLSubset comment formatter, should assess exposure and upgrade to Apache Roller 6.1.6 or later.
Why it matters
CVE-2026-91204 is a Cross-site Scripting (XSS) vulnerability in Apache Roller 6.1.5 that allows an attacker to execute script in a visitor's browser. Defenders of Apache Roller sites should assess exposure and take action to prevent potential XSS attacks.
- Defenders should verify if their Apache Roller sites have HTML comments enabled and the HTMLSubset comment formatter, and assess exposure to potential XSS attacks.
- Defenders should prioritize upgrading to Apache Roller 6.1.6 or later to restrict restored links to http, https, and mailto URIs.
- Defenders should monitor for suspicious comments and activity on their Apache Roller sites.
Technical summary
The CVE record describes a Cross-site Scripting (XSS) vulnerability in Apache Roller 6.1.5. An anonymous remote attacker can store a comment containing a javascript: URI link that survives HTML comment formatting and can execute script in the browser of a visitor who clicks it. This affects only sites that enable HTML in comments (users.comments.htmlenabled=true) together with the HTMLSubset comment formatter; comment moderation, where enabled, delays publication.
Defensive priority
Upgrade to Apache Roller 6.1.6 or later to restrict restored links to http, https, and mailto URIs.
Recommended defensive actions
- Upgrade to Apache Roller 6.1.6 or later
- Review and restrict HTML comments and formatting
- Monitor for suspicious comments and activity
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The CVE record and NVD entry provide details on the XSS vulnerability in Apache Roller 6.1.5. The vulnerability allows an attacker to store a malicious comment that can execute script in a visitor's browser.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-91204 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-91204
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-91204 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-91204
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/apache/roller/pull/190
-
Source reference
Unverified legacy reference
URL: https://lists.apache.org/thread/4qzp8m0438056l5t6m6719ob79gx72lz
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.