Skip to content
feed: live
>_0dayNews
CVE Record
[ CRITICAL ]CVE-2026-82384

Apache Roller XML-RPC Deserialization Allows Unauthenticated RCE

Deserialization of untrusted data in Apache Roller 6.1.5 XML-RPC endpoint lets an unauthenticated attacker execute arbitrary code remotely. CVSS 9.8 critical.

cat cve-2026-82384.json
Vendor
Apache Software Foundation
Product
Apache Roller
CVSS
9.8
EPSS (exploit probability)
0.8%
Status
patched
Published

CVE-2026-82384 is a deserialization of untrusted data vulnerability in Apache Roller 6.1.5. The XML-RPC endpoint accepts vendor-extended method calls and deserializes attacker-controlled bytes, allowing an unauthenticated remote attacker to execute arbitrary code on the server.

No authentication is required to reach the XML-RPC endpoint, which is commonly exposed on public-facing Roller installations.

What to do: Upgrade Apache Roller to a patched version. If an immediate upgrade is not possible, restrict external access to the XML-RPC endpoint at the network layer. See the NVD record and the Apache Roller GitHub fix for details.