Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-82384: Apache Roller can run attacker code via XML-RPC
CVE-2026-82384 · published 12 days ago
Summary
Apache Roller version 6.1.5 lets anyone send specially crafted XML-RPC messages that are processed before anyone logs in. This can let an attacker make the server execute their own code, potentially taking control of the system. Upgrade to Apache Roller 6.1.6 or newer, which blocks these dangerous messages.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| apache software foundation | apache roller | 6.1.5 |
Original advisory text
Apache Roller: Unauthenticated deserialization in the XML-RPC endpoint
Deserialization of Untrusted Data in Apache Roller 6.1.5 allows an unauthenticated remote attacker to cause deserialization of attacker-controlled bytes, because the XML-RPC endpoint accepts vendor extension types that are deserialized during request parsing, before authentication. The servlet is mapped unconditionally, so parsing occurs even when the global XML-RPC feature is set to disabled; no non-default configuration is required for this path. This can lead to remote code execution. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which disables the extension types and rejects requests when the XML-RPC feature is disabled.
References
- https://lists.apache.org/thread/21p1dh6x179gmcdpw84kkx9yclrdp410
- http://www.openwall.com/lists/oss-security/2026/09/25/17
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82384... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-82384 Vendor Advisory
- https://github.com/apache/roller/pull/171
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-502Deserialization of Untrusted Data
Timeline
Published28 Sep 2026
Updated9 Oct 2026
First seen28 Sep 2026
Track software like this
Free during beta