Skip to content
Exploit for CVE-2026

Exploit for CVE-2026

Sploitus • September 28, 2026

Python 3 PoC for **[CVE-2026-82384]( — **Apache Roller 6.1.5** unauthenticated **Java deserialization** on the legacy **XML-RPC** servlet.

**PoC page:** [

[Apache Roller]( is a Java-based, multi-user **blog server** (historically “Roller Weblogger”). Deployments are usually Tomcat WARs with a UI under `/roller-ui/` and legacy **Blogger / MetaWeblog** APIs over **XML-RPC** at `/roller-services/xmlrpc`. Roller **6.1.5** (Sep 2025) fixed an unrelated session issue (CVE-2025-24859) but left the XML-RPC stack in a dangerous configuration for this CVE.

**CVE-2026-82384** is **deserialization of untrusted data** (CWE-502) on the **XML-RPC endpoint**:

1. Roller’s `XmlRpcServlet` is configured with **`enabledForExtensions=true`**, so the Apache ws-xmlrpc library accepts **vendor extension types**, including **`ex:serializable`** — a **base64-encoded Java serialized object**.

2. That parsing runs **during HTTP request handling**, **before** Blogger/MetaWeblog **authentication** is evaluated.

3. The servlet mapping is **always present** in `web.xml`, so the parser still runs **even when administrators disable XML-RPC** in Roller settings (`webservices.enableXmlRpc=false`). Disabling the feature in the UI does **not** close this pre-auth path on **6.1.5**.

4. A remote attacker sends a crafted XML-RPC body; the server **deserializes** attacker bytes → **remote code execution** in the JVM (same class of bug as historic **CVE-2016-5003** in ws-xmlrpc / Archiva).

**Affected:** **Apache Roller 6.1.5** only (per vendor advisory).

**Fixed:** **Apache Roller 6.1.6+** ([PR #171]( `enabledForExtensions=false`, and requests rejected when XML-RPC is disabled globally.

| **CVSS 3.1** | **9.8 Critical** — `AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H` |

| **Auth** | **None** for the deserialization primitive |

| **Vendor** | Apache Software Foundation |

| **Endpoint** | `POST /roller-services/xmlrpc` (also try `/roller/roller-services/xmlrpc`) |

| **Trigger** | `BASE64` inside a `methodCall` |

| **Gadget chain** | Depends on classpath (Commons Collections, etc.); often generated with **ysoserial** |

| **Impact** | RCE as the Tomcat/Roller OS user; typically full control of blog data and host pivot |

| **`check`** | Finds Roller fingerprints, locates XML-RPC URL, optional **`--probe-deser`** (sends `ex:serializable` probe bytes) |

| **`exploit`** | Posts **your** serialized payload (file, base64, or **ysoserial** via `--ysoserial-jar`) |

| **Mass** | `--list targets.txt --mode exploit -j N` — parallel bulk with JSONL + **`exploited.txt`** |

**PoCbit fields:** `pocbit`, `pocbit_catalog`, `pocbit_page` on every JSONL row.

**CLI:** color banner, `[HIT]` / `[EXPLOIT]` / `[FAIL]` lines (disable with `--no-color`).

This repository **does not ship live RCE gadget chains** (classpath-dependent). For real exploitation, provide **ysoserial** output or a verified payload file.

- **Java** + **[ysoserial]( JAR on the attacker machine

- Example gadgets: `URLDNS` (out-of-band proof), `CommonsCollections6` (command execution on typical Roller classpath — **lab verify first**)

python poc.py -u --mode check

python poc.py -u --mode check --probe-deser

python poc.py --list targets.example.txt --mode check -j 12

# OOB DNS proof (replace with your collaborator)

python poc.py -u --mode exploit \

--ysoserial-jar ysoserial.jar --ysoserial-gadget URLDNS \

python poc.py -u --mode exploit --payload-file chain.b64

python poc.py -u --mode exploit --payload-file payload.bin

python poc.py --list targets.txt --mode exploit \

--ysoserial-jar ysoserial.jar --ysoserial-gadget URLDNS \

- `cve_2026_82384_exploit.jsonl` — per-target JSON

- `exploited.txt` — targets where payload was accepted / OOB sent

On **6.1.5**, parsing this body can deserialize before any method handler enforces credentials.

1. **Upgrade to Roller 6.1.6+** immediately.

2. Until patched: **block** `/roller-services/xmlrpc` at reverse proxy / WAF (allowlist admin IPs only).

3. Inventory: for `Apache Roller`, `/roller-ui/`, port 8080/8443 blog hosts.

4. Related same-release issues: **CVE-2026-82377** (XML-RPC authz), **CVE-2026-82386** (XXE in bookmark import) — also fixed in **6.1.6**.

Confirm version **6.1.5** from footer, page, or `WEB-INF` / release notes before treating as exploitable.

Use only on systems you are authorized to test. Deserialization exploits can destroy data and violate law if misused.