
CVE-2026-82384 - Apache Roller 6.1.5 accepts ex:serializable on /roller-services/xmlrpc before auth. UI “disable XML-RPC” doesn’t remove the servlet on 6.1.5. PoC: 📷https://pocbit.org/pocs/cve-2026-82384 #Java #RCE #WebSecurity #Pentest
Signal is active with 3 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
Deserialization of Untrusted Data in Apache Roller 6.1.5 allows an unauthenticated remote attacker to cause deserialization of attacker-controlled bytes, because the XML-RPC endpoint accepts vendor extension types that are deserialized during request parsing, before authentication. The servlet is mapped unconditionally, so parsing occurs even when the global XML-RPC feature is set to disabled; no non-default configuration is required for this path. This can lead to remote code execution. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which disables the extension types and rejects requests when the XML-RPC feature is disabled.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

CVE-2026-82384 - Apache Roller 6.1.5 accepts ex:serializable on /roller-services/xmlrpc before auth. UI “disable XML-RPC” doesn’t remove the servlet on 6.1.5. PoC: 📷https://pocbit.org/pocs/cve-2026-82384 #Java #RCE #WebSecurity #Pentest

🪵 Apache Roller 6.1.5: unauthenticated deserialization via the XML-RPC endpoint. CVSS 9.8 - no auth, no interaction, full RCE potential. CVE-2026-82384 #cybersecurity #ciso #vulnerabilities #mssp https://secalerts.co/vulnerability/CVE-2026-82384?utm_campaign=x https://t.co/8YJgEOBfmu

🚨 Critical - Apache Roller XML-RPC RCE and Authorization Bypass (CVE-2026-82384, CVE-2026-82377) Apache Roller 6.1.5 has two serious XML-RPC flaws: CVE-2026-82384 allows unauthenticated attackers to trigger pre-auth deserialization of attacker-controlled data, potentially leading to RCE, even when global XML-RPC is disabled. CVE-2026-82377 allows authenticated users to read, modify, or delete content in other weblogs when global XML-RPC is enabled, due to missing per-weblog authorization checks. 👉 Affected: Apache Roller 6.1.5 | Upgrade to 6.1.6