CVE-2026-82384 PUBLISHED

Apache Roller: Unauthenticated deserialization in the XML-RPC endpoint

Assigner: apache
Reserved: 28.08.2026 Published: 28.09.2026 Updated: 29.09.2026

Deserialization of Untrusted Data in Apache Roller 6.1.5 allows an unauthenticated remote attacker to cause deserialization of attacker-controlled bytes, because the XML-RPC endpoint accepts vendor extension types that are deserialized during request parsing, before authentication. The servlet is mapped unconditionally, so parsing occurs even when the global XML-RPC feature is set to disabled; no non-default configuration is required for this path. This can lead to remote code execution. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which disables the extension types and rejects requests when the XML-RPC feature is disabled.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor Apache Software Foundation
Product Apache Roller
Versions Default: unknown
  • Version 6.1.5 is affected

Credits

  • n0mi1k finder

References

Problem Types

  • CWE-502: Deserialization of Untrusted Data CWE