CVE-2026-82384: Apache Roller: Unauthenticated deserialization in the XML-RPC endpoint
Apache Roller 6.1.5 has unauthenticated XML-RPC deserialization rated CVSS 9.8.
Apache disclosed CVE-2026-82384, a critical deserialization flaw in Apache Roller 6.1.5 with CVSS 3.1 9.8. The XML-RPC endpoint accepts vendor extension types that are deserialized while parsing a request, before authentication. An unauthenticated remote attacker can therefore cause deserialization of attacker-controlled bytes, with high impact on confidentiality, integrity, and availability. The advisory does not say the flaw is being exploited.
64