Apache Roller XML-RPC Deserialization Allows Unauthenticated RCE
Deserialization of untrusted data in Apache Roller 6.1.5 XML-RPC endpoint lets an unauthenticated attacker execute arbitrary code remotely. CVSS 9.8 critical.
- Vendor
- Apache Software Foundation
- Product
- Apache Roller
- CVSS
- 9.8
- EPSS (exploit probability)
- 0.8%
- Status
- patched
- Published
CVE-2026-82384 is a deserialization of untrusted data vulnerability in Apache Roller 6.1.5. The XML-RPC endpoint accepts vendor-extended method calls and deserializes attacker-controlled bytes, allowing an unauthenticated remote attacker to execute arbitrary code on the server.
No authentication is required to reach the XML-RPC endpoint, which is commonly exposed on public-facing Roller installations.
What to do: Upgrade Apache Roller to a patched version. If an immediate upgrade is not possible, restrict external access to the XML-RPC endpoint at the network layer. See the NVD record and the Apache Roller GitHub fix for details.
