Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-82384: Apache Roller can run attacker code via XML-RPC

CVE-2026-82384 · published 12 days ago
Summary

Apache Roller version 6.1.5 lets anyone send specially crafted XML-RPC messages that are processed before anyone logs in. This can let an attacker make the server execute their own code, potentially taking control of the system. Upgrade to Apache Roller 6.1.6 or newer, which blocks these dangerous messages.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
apache software foundation apache roller 6.1.5
Original advisory text
Apache Roller: Unauthenticated deserialization in the XML-RPC endpoint
Deserialization of Untrusted Data in Apache Roller 6.1.5 allows an unauthenticated remote attacker to cause deserialization of attacker-controlled bytes, because the XML-RPC endpoint accepts vendor extension types that are deserialized during request parsing, before authentication. The servlet is mapped unconditionally, so parsing occurs even when the global XML-RPC feature is set to disabled; no non-default configuration is required for this path. This can lead to remote code execution. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which disables the extension types and rejects requests when the XML-RPC feature is disabled.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.8 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-502Deserialization of Untrusted Data
Timeline
Published28 Sep 2026
Updated9 Oct 2026
First seen28 Sep 2026
Sources
CVE-2026-82384 · MITRE
Track software like this
Free during beta