Python 3 PoC for **[CVE-2026-82384]( — **Apache Roller 6.1.5** unauthenticated **Java deserialization** on the legacy **XML-RPC** servlet.
**PoC page:** [
[Apache Roller]( is a Java-based, multi-user **blog server** (historically “Roller Weblogger”). Deployments are usually Tomcat WARs with a UI under `/roller-ui/` and legacy **Blogger / MetaWeblog** APIs over **XML-RPC** at `/roller-services/xmlrpc`. Roller **6.1.5** (Sep 2025) fixed an unrelated session issue (CVE-2025-24859) but left the XML-RPC stack in a dangerous configuration for this CVE.
**CVE-2026-82384** is **deserialization of untrusted data** (CWE-502) on the **XML-RPC endpoint**:
1. Roller’s `XmlRpcServlet` is configured with **`enabledForExtensions=true`**, so the Apache ws-xmlrpc library accepts **vendor extension types**, including **`ex:serializable`** — a **base64-encoded Java serialized object**.
2. That parsing runs **during HTTP request handling**, **before** Blogger/MetaWeblog **authentication** is evaluated.
3. The servlet mapping is **always present** in `web.xml`, so the parser still runs **even when administrators disable XML-RPC** in Roller settings (`webservices.enableXmlRpc=false`). Disabling the feature in the UI does **not** close this pre-auth path on **6.1.5**.
4. A remote attacker sends a crafted XML-RPC body; the server **deserializes** attacker bytes → **remote code execution** in the JVM (same class of bug as historic **CVE-2016-5003** in ws-xmlrpc / Archiva).
**Affected:** **Apache Roller 6.1.5** only (per vendor advisory).
**Fixed:** **Apache Roller 6.1.6+** ([PR #171]( `enabledForExtensions=false`, and requests rejected when XML-RPC is disabled globally.
| **CVSS 3.1** | **9.8 Critical** — `AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H` |
| **Auth** | **None** for the deserialization primitive |
| **Vendor** | Apache Software Foundation |
| **Endpoint** | `POST /roller-services/xmlrpc` (also try `/roller/roller-services/xmlrpc`) |
| **Trigger** | `BASE64` inside a `methodCall` |
| **Gadget chain** | Depends on classpath (Commons Collections, etc.); often generated with **ysoserial** |
| **Impact** | RCE as the Tomcat/Roller OS user; typically full control of blog data and host pivot |
| **`check`** | Finds Roller fingerprints, locates XML-RPC URL, optional **`--probe-deser`** (sends `ex:serializable` probe bytes) |
| **`exploit`** | Posts **your** serialized payload (file, base64, or **ysoserial** via `--ysoserial-jar`) |
| **Mass** | `--list targets.txt --mode exploit -j N` — parallel bulk with JSONL + **`exploited.txt`** |
**PoCbit fields:** `pocbit`, `pocbit_catalog`, `pocbit_page` on every JSONL row.
**CLI:** color banner, `[HIT]` / `[EXPLOIT]` / `[FAIL]` lines (disable with `--no-color`).
This repository **does not ship live RCE gadget chains** (classpath-dependent). For real exploitation, provide **ysoserial** output or a verified payload file.
- **Java** + **[ysoserial]( JAR on the attacker machine
- Example gadgets: `URLDNS` (out-of-band proof), `CommonsCollections6` (command execution on typical Roller classpath — **lab verify first**)
python poc.py -u --mode check
python poc.py -u --mode check --probe-deser
python poc.py --list targets.example.txt --mode check -j 12
# OOB DNS proof (replace with your collaborator)
python poc.py -u --mode exploit \
--ysoserial-jar ysoserial.jar --ysoserial-gadget URLDNS \
python poc.py -u --mode exploit --payload-file chain.b64
python poc.py -u --mode exploit --payload-file payload.bin
python poc.py --list targets.txt --mode exploit \
--ysoserial-jar ysoserial.jar --ysoserial-gadget URLDNS \
- `cve_2026_82384_exploit.jsonl` — per-target JSON
- `exploited.txt` — targets where payload was accepted / OOB sent
On **6.1.5**, parsing this body can deserialize before any method handler enforces credentials.
1. **Upgrade to Roller 6.1.6+** immediately.
2. Until patched: **block** `/roller-services/xmlrpc` at reverse proxy / WAF (allowlist admin IPs only).
3. Inventory: for `Apache Roller`, `/roller-ui/`, port 8080/8443 blog hosts.
4. Related same-release issues: **CVE-2026-82377** (XML-RPC authz), **CVE-2026-82386** (XXE in bookmark import) — also fixed in **6.1.6**.
Confirm version **6.1.5** from footer, page, or `WEB-INF` / release notes before treating as exploitable.
Use only on systems you are authorized to test. Deserialization exploits can destroy data and violate law if misused.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
