
🚨 Critical - Apache Roller XML-RPC RCE and Authorization Bypass (CVE-2026-82384, CVE-2026-82377) Apache Roller 6.1.5 has two serious XML-RPC flaws: CVE-2026-82384 allows unauthenticated attackers to trigger pre-auth deserialization of attacker-controlled data, potentially leading to RCE, even when global XML-RPC is disabled. CVE-2026-82377 allows authenticated users to read, modify, or delete content in other weblogs when global XML-RPC is enabled, due to missing per-weblog authorization checks. 👉 Affected: Apache Roller 6.1.5 | Upgrade to 6.1.6
