Skip to content
Critical RCE Vulnerability in Apache Roller 6.1.5 Disclosed

Critical RCE Vulnerability in Apache Roller 6.1.5 Disclosed

First seen 29 Sep 2026, 04:06 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 29, 2026 at 05:09 UTC
  • •CVE-2026-82384 allows RCE via Apache Roller 6.1.5's XML-RPC endpoint.
  • •Attackers can exploit the flaw without authentication, leading to critical impacts.
  • •Users must upgrade to Apache Roller 6.1.6+ to mitigate the risk.

A critical vulnerability, CVE-2026-82384, was disclosed for Apache Roller 6.1.5, allowing unauthenticated remote attackers to exploit deserialization of untrusted data via the XML-RPC endpoint. The flaw arises from the server's acceptance of vendor extension types, which are deserialized before authentication checks. This vulnerability can lead to remote code execution (RCE) in the Java Virtual Machine (JVM). The affected version is 6.1.5, and users are advised to upgrade to 6.1.6 or later, which disables the dangerous extension types. The CVSS score for this vulnerability is 9.8, indicating a critical threat. The first public proof-of-concept (PoC) was released on the same day as the vulnerability disclosure, September 28, 2026. This vulnerability is particularly concerning as it allows full control over blog data and potential host pivoting. No non-default configuration is required to exploit this vulnerability.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2017-10-27
CVE-2016-5003 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-04-14
CVE-2025-24859 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-28
CVE-2026-82384 published
Apache Roller 6.1.5 vulnerability disclosed, allowing RCE through XML-RPC deserialization.
Sploitus
2026-09-28
First public PoC released
Public proof-of-concept code for CVE-2026-82384 made available, demonstrating the exploit.
Mondoo
2026-09-28
CVE-2026-82377 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-28
CVE-2026-82386 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

More articles in this cluster (4)

Following this threat?

Track Apache Software Foundation and CVE-2016-5003 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed