CRITICAL
9.8 CVE-2026-82384 Published 28 Sept 2026
Apache Roller XML-RPC Deserialization RCE Vulnerability
Worried this affects your website?
Apache Roller 6.1.5 contains a Deserialization of Untrusted Data vulnerability in its XML-RPC endpoint. An unauthenticated remote attacker can cause deserialization of attacker-controlled bytes because the endpoint accepts vendor extension types that are deserialized during request parsing, before authentication.
- Affected version: Apache Roller 6.1.5
- Attack vector: unauthenticated remote attacker via XML-RPC endpoint
- Impact: remote code execution
- Fix: upgrade to Apache Roller 6.1.6 or later, which disables the extension types and rejects requests when the XML-RPC feature is disabled
The servlet is mapped unconditionally, so parsing occurs even when the global XML-RPC feature is set to disabled; no non-default configuration is required for this path.
Reference: CVE-2026-82384 on NVD
← Back to Security News