https://seclists.org/oss-sec/2026/q3/949: CVE-2026-82384: Apache Roller: Unauthenticated deserialization in the XML-RPC endpoint
Published Sep 25, 2026
·Updated
Affected Software
1 affected component
Apache Roller=6.1.5
Frequently Asked Questions
1
Are deployments with XML-RPC disabled still exposed?
Yes. In Apache Roller 6.1.5, the XML-RPC servlet is mapped unconditionally and parses requests before authentication, even when the global XML-RPC feature is disabled.
2
What does an attacker need to exploit this issue?
An attacker can exploit the affected endpoint remotely without authentication or user interaction by sending attacker-controlled data using XML-RPC vendor extension types. No non-default configuration is required.
3
Which versions need to be remediated?
Apache Roller 6.1.5 is identified as affected. Upgrade to Apache Roller 6.1.6 or later, which disables the extension types and rejects requests when XML-RPC is disabled.