Description
Deserialization of Untrusted Data in Apache Roller 6.1.5 allows an unauthenticated remote attacker to cause deserialization of attacker-controlled bytes, because the XML-RPC endpoint accepts vendor extension types that are deserialized during request parsing, before authentication. The servlet is mapped unconditionally, so parsing occurs even when the global XML-RPC feature is set to disabled; no non-default configuration is required for this path. This can lead to remote code execution. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which disables the extension types and rejects requests when the XML-RPC feature is disabled.
Published: 2026-09-28
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution via XML-RPC Deserialization
Action: Apply Patch
AI Analysis

Impact

The vulnerability arises from Apache Roller’s XML‑RPC endpoint deserializing vendor extension types without authenticating the requester. Because the servlet processes requests even when the global XML‑RPC feature is disabled, any remote entity can supply malicious XML payloads that trigger deserialization of attacker‑controlled bytes. This flaw can lead to arbitrary code execution on the host running the Roller instance.

Affected Systems

The affected product is Apache Roller version 6.1.5. Users running this version—or any sub‑release that has not yet been updated to 6.1.6 or later—are at risk. No special configuration is required for the vulnerability to be exploitable; the default deployment already exposes the vulnerable endpoint.

Risk and Exploitability

The CVSS score of 9.8 indicates a critical severity. The EPSS score is currently unavailable, but vulnerability disclosure and historical activity suggest that exploitation is possible. The vulnerability is not listed in CISA KEV yet. The likely attack vector is an unauthenticated remote request to the XML‑RPC endpoint. An attacker can send crafted XML data that the server will deserialize before any authentication check, potentially executing arbitrary code on the server.

Generated by OpenCVE AI on September 28, 2026 at 09:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Apache Roller 6.1.6 or later, which disables extension types and rejects requests when XML‑RPC is disabled.
  • If a patch cannot be applied immediately, disable the XML‑RPC feature in the Roller configuration to eliminate the vulnerable endpoint.
  • Restrict network access to the XML‑RPC port using firewalls or access control lists so that only trusted hosts can reach the endpoint.

Generated by OpenCVE AI on September 28, 2026 at 09:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache roller
Vendors & Products Apache
Apache roller

Mon, 28 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
References

Mon, 28 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data in Apache Roller 6.1.5 allows an unauthenticated remote attacker to cause deserialization of attacker-controlled bytes, because the XML-RPC endpoint accepts vendor extension types that are deserialized during request parsing, before authentication. The servlet is mapped unconditionally, so parsing occurs even when the global XML-RPC feature is set to disabled; no non-default configuration is required for this path. This can lead to remote code execution. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which disables the extension types and rejects requests when the XML-RPC feature is disabled.
Title Apache Roller: Unauthenticated deserialization in the XML-RPC endpoint
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-28T13:31:30.730Z

Reserved: 2026-08-28T20:52:42.494Z

Link: CVE-2026-82384

cve-icon Vulnrichment

Updated: 2026-09-28T08:21:44.753Z

cve-icon NVD

Status : Deferred

Published: 2026-09-28T08:16:42.273

Modified: 2026-09-28T14:29:44.860

Link: CVE-2026-82384

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T16:23:13Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data