CVE-2026-82384: Apache Roller: Unauthenticated deserialization in the XML-RPC endpoint
Apache Roller 6.1.5 has unauthenticated XML-RPC deserialization rated CVSS 9.8.
Apache disclosed CVE-2026-82384, a critical deserialization flaw in Apache Roller 6.1.5 with CVSS 3.1 9.8. The XML-RPC endpoint accepts vendor extension types that are deserialized while parsing a request, before authentication. An unauthenticated remote attacker can therefore cause deserialization of attacker-controlled bytes, with high impact on confidentiality, integrity, and availability. The advisory does not say the flaw is being exploited.
- Unauthenticated remote deserialization before authentication
- XML-RPC endpoint accepts vendor extension types
- Affects Apache Roller 6.1.5
- CVSS 3.1 9.8 with full confidentiality, integrity, and availability impact
- No in-the-wild exploitation stated
Vulnerabilities mentionedAll →
- published —
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-82384 | NVD description · AI analysis pending | — | — | — | — | — |
Posted by David M. Johnson on Sep 25 Severity: Critical CVSS 3.1: 9.8 (critical) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected versions: - Apache Roller 6.1.5 Description: Deserialization of Untrusted Data in Apache Roller 6.1.5 allows an unauthenticated remote attacker to cause deserialization of attacker-controlled bytes, because the XML-RPC endpoint accepts vendor extension types that are deserialized during request parsing, before authentication. The servlet...
This source does not provide full text. Read it at seclists.org.