https://seclists.org/oss-sec/2026/q3/949: CVE-2026-82384: Apache Roller: Unauthenticated deserialization in the XML-RPC endpoint

Published Sep 25, 2026
·
Updated

Affected Software

1 affected component
Apache Roller=6.1.5

Frequently Asked Questions

1

Are deployments with XML-RPC disabled still exposed?

Yes. In Apache Roller 6.1.5, the XML-RPC servlet is mapped unconditionally and parses requests before authentication, even when the global XML-RPC feature is disabled.

2

What does an attacker need to exploit this issue?

An attacker can exploit the affected endpoint remotely without authentication or user interaction by sending attacker-controlled data using XML-RPC vendor extension types. No non-default configuration is required.

3

Which versions need to be remediated?

Apache Roller 6.1.5 is identified as affected. Upgrade to Apache Roller 6.1.6 or later, which disables the extension types and rejects requests when XML-RPC is disabled.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203