CRITICAL 9.8 CVE-2026-82384 Published 28 Sept 2026

Apache Roller XML-RPC Deserialization RCE Vulnerability

Worried this affects your website?

Apache Roller 6.1.5 contains a Deserialization of Untrusted Data vulnerability in its XML-RPC endpoint. An unauthenticated remote attacker can cause deserialization of attacker-controlled bytes because the endpoint accepts vendor extension types that are deserialized during request parsing, before authentication.

  • Affected version: Apache Roller 6.1.5
  • Attack vector: unauthenticated remote attacker via XML-RPC endpoint
  • Impact: remote code execution
  • Fix: upgrade to Apache Roller 6.1.6 or later, which disables the extension types and rejects requests when the XML-RPC feature is disabled

The servlet is mapped unconditionally, so parsing occurs even when the global XML-RPC feature is set to disabled; no non-default configuration is required for this path.

Reference: CVE-2026-82384 on NVD

← Back to Security News