CVE-2026-82384
Received Received - Intake

Deserialization of Untrusted Data in Apache Roller

Vulnerability report for CVE-2026-82384, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: Apache Software Foundation

Description

Deserialization of Untrusted Data in Apache Roller 6.1.5 allows an unauthenticated remote attacker to cause deserialization of attacker-controlled bytes, because the XML-RPC endpoint accepts vendor extension types that are deserialized during request parsing, before authentication. The servlet is mapped unconditionally, so parsing occurs even when the global XML-RPC feature is set to disabled; no non-default configuration is required for this path. This can lead to remote code execution. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which disables the extension types and rejects requests when the XML-RPC feature is disabled.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
apache roller 6.1.5
apache roller 6.1.6

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-502 The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a deserialization flaw in Apache Roller 6.1.5 where an unauthenticated remote attacker can execute arbitrary code by sending specially crafted data to the XML-RPC endpoint. The issue occurs because the endpoint processes vendor extension types during request parsing before authentication, even when XML-RPC is disabled. This allows remote code execution without requiring special configuration.

Detection Guidance

To detect this vulnerability, check if Apache Roller 6.1.5 is running and if the XML-RPC servlet is accessible. Verify the version by inspecting the application or server logs for Apache Roller. If the version is 6.1.5, the system is likely vulnerable. Additionally, test if the XML-RPC endpoint responds to requests even when the feature is disabled.

Impact Analysis

An attacker could exploit this to gain control of the affected Apache Roller instance, potentially stealing data, installing malware, or disrupting services. Since the endpoint is accessible without authentication and even when XML-RPC is disabled, the attack surface is broad and requires immediate patching.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, violating GDPR's data protection requirements or HIPAA's safeguards for protected health information. Organizations using vulnerable versions may face compliance violations, legal penalties, and reputational damage if exploited.

Mitigation Strategies

Immediately upgrade Apache Roller to version 6.1.6 or later to disable vulnerable XML-RPC extension types and enforce proper configuration checks. Ensure the XML-RPC feature is disabled in the settings and verify that the endpoint rejects all requests when disabled.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82384. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart