Skip to content
feed: live
>_0dayNews
apache

Apache Roller Patches Critical XML-RPC Deserialization Bug

Apache Roller 6.1.5 has four patched vulnerabilities, including a CVSS 9.8 deserialization flaw allowing unauthenticated RCE via the XML-RPC endpoint.

Apache Roller Patches Critical XML-RPC Deserialization Bug
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
fuseMarisol "Fuse" Delgado·Published ·2 min read

Apache has patched four vulnerabilities in Roller 6.1.5, the Java blogging platform used on a range of self-hosted sites and intranets. Two are critical severity. Patch now.

The flaws

CVE-2026-82384 (CVSS 9.8, critical) is a deserialization of untrusted data flaw in the XML-RPC endpoint. An unauthenticated remote attacker can submit attacker-controlled bytes to the endpoint and achieve arbitrary code execution. This is the highest-risk flaw in the batch: no authentication is needed, and the XML-RPC endpoint is commonly reachable from the internet on a public Roller install. See the GitHub pull request and NVD record.

CVE-2026-82378 (CVSS 9.0, critical) is an incorrect authorization flaw in the OAuth 1.0a endpoint. An unauthenticated attacker who obtains an outstanding request token for a site-wide OAuth consumer can abuse the authorization endpoint to obtain an access token for any user without the normal user-approval step. See the GitHub pull request and NVD record.

CVE-2026-82383 (CVSS 8.2, high) is a missing authentication flaw. An unauthenticated attacker can reach a configuration endpoint that should require admin credentials and persistently change a site-wide setting: specifically the frontpage weblog selection. Details in GitHub PR #170.

CVE-2026-82379 (CVSS 7.7, high) is an authentication bypass via capture-replay in Apache Roller’s WSSE digest authentication for AtomPub. An attacker who captures a valid WSSE digest header can replay it to gain the victim’s AtomPub authority because nonce tracking that would prevent reuse is not in place. Details in GitHub PR #166.

What to do

Upgrade to a patched version of Apache Roller. All four CVEs are fixed upstream. Confirm the current patched build version against the Apache Roller project site and apply it.

If an immediate upgrade is not possible, assess whether the XML-RPC endpoint (CVE-2026-82384) and OAuth 1.0a endpoint (CVE-2026-82378) are reachable from the public internet and restrict network access to those paths until a patched build is in place. Those two are the higher-risk paths given their CVSS scores and the lack of any authentication requirement.

Apache patch activity in 2026

This is the second significant Apache project patch event this month. In mid-September, Apache Syncope patched seven critical flaws, including remote code execution and privilege escalation issues. Earlier in the year, Apache Tomcat’s EncryptInterceptor bypass was added to CISA’s KEV catalog. Organizations running Apache Software Foundation components in production should subscribe to the Apache security announcements mailing list to get notification ahead of public CVE publication.

Related CVEs
  • [ CRITICAL ]CVE-2026-82384Apache Roller XML-RPC Deserialization Allows Unauthenticated RCE
  • [ HIGH ]CVE-2026-82383Apache Roller Missing Auth Lets Attackers Change Site Configuration
  • [ HIGH ]CVE-2026-82379Apache Roller WSSE Auth Bypass via Digest Replay
  • [ CRITICAL ]CVE-2026-82378Apache Roller OAuth 1.0a Authorization Bypass Allows Token Theft

Found this useful? Share it.