CVE-CVE-2026-82384
Severity
CRITICAL
CVSS Score
9.8
Description
Deserialization of Untrusted Data in Apache Roller 6.1.5 allows an unauthenticated remote attacker to cause deserialization of attacker-controlled bytes, because the XML-RPC endpoint accepts vendor extension types that are deserialized during request parsing, before authentication. The servlet is mapped unconditionally, so parsing occurs even when the global XML-RPC feature is set to disabled; no non-default configuration is required for this path. This can lead to remote code execution. Users a...
PoCs for CVE-CVE-2026-82384
CVE-2026-82384
RCE
Python
0
murrez
2026-09-28