CVE-2026-82384

LOWCVSS 9.8 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Deserialization of Untrusted Data in Apache Roller 6.1.5 allows an unauthenticated remote attacker to cause deserialization of attacker-controlled bytes, because the XML-RPC endpoint accepts vendor extension types that are deserialized during request parsing, before authentication. The servlet is mapped unconditionally, so parsing occurs even when the global XML-RPC feature is set to disabled; no non-default configuration is required for this path. This can lead to remote code execution. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which disables the extension types and rejects requests when the XML-RPC feature is disabled.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-09-28: 309-28
Referenced assets2 URLs
Full discourse3 posts
  • mürrez@murrezsec

    CVE-2026-82384 - Apache Roller 6.1.5 accepts ex:serializable on /roller-services/xmlrpc before auth. UI “disable XML-RPC” doesn’t remove the servlet on 6.1.5. PoC: 📷https://pocbit.org/pocs/cve-2026-82384 #Java #RCE #WebSecurity #Pentest

    0001042
    620 followersView on X
  • SecAlerts@SecAlertsCo

    🪵 Apache Roller 6.1.5: unauthenticated deserialization via the XML-RPC endpoint. CVSS 9.8 - no auth, no interaction, full RCE potential. CVE-2026-82384 #cybersecurity #ciso #vulnerabilities #mssp https://secalerts.co/vulnerability/CVE-2026-82384?utm_campaign=x https://t.co/8YJgEOBfmu

    0000052
    890 followersView on X
  • Upwind Security MDR@UpwindMDR

    🚨 Critical - Apache Roller XML-RPC RCE and Authorization Bypass (CVE-2026-82384, CVE-2026-82377) Apache Roller 6.1.5 has two serious XML-RPC flaws: CVE-2026-82384 allows unauthenticated attackers to trigger pre-auth deserialization of attacker-controlled data, potentially leading to RCE, even when global XML-RPC is disabled. CVE-2026-82377 allows authenticated users to read, modify, or delete content in other weblogs when global XML-RPC is enabled, due to missing per-weblog authorization checks. 👉 Affected: Apache Roller 6.1.5 | Upgrade to 6.1.6

    0000032
    308 followersView on X

Explore more