POCBIT

Telegram — New PoC releases & critical CVE alerts

You can join our Telegram channel to get instant updates on new PoC releases and critical CVE alerts.

Join @pocbit
Web appcritical

CVE-2026-82384 — Apache Roller 6.1.5 XML-RPC Pre-Auth Java Deserialization

September 28, 2026 · 108 views

Unauthenticated Java deserialization (CWE-502) on Apache Roller 6.1.5 legacy XML-RPC servlet: enabledForExtensions allows ex:serializable before Blogger/MetaWeblog auth; mapping stays active even when XML-RPC is disabled in UI. Pre-auth RCE via attacker-controlled serialized objects (ysoserial/classpath gadgets). Fixed in 6.1.6+. CVSS 9.8 Critical. Python PoC: check, probe-deser, exploit, mass -j.

#apache#roller#java#deserialization#xml-rpc#unauthenticated#rce#blog

CVE:

CVE-2026-82384

Date:

2026-09-28

Severity:

CRITICAL

Exploit source

PoC code is available to registered members only.

Description

Overview

CVE-2026-82384 affects Apache Roller 6.1.5 only — deserialization of untrusted data (CWE-502) on the legacy XML-RPC endpoint.

Apache Roller is a Java multi-user blog server (Tomcat WAR, UI under /roller-ui/, APIs at /roller-services/xmlrpc).

| | | |---|---| | Affected | Apache Roller 6.1.5 | | Fixed | 6.1.6+ (PR #171: enabledForExtensions=false, reject when XML-RPC disabled) | | Endpoint | POST /roller-services/xmlrpc (also /roller/roller-services/xmlrpc) | | Trigger | <ex:serializable> base64 Java object in XML-RPC before auth | | Auth | None for the deserialization primitive | | CVSS 3.1 | 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) | | Credit | n0mi1k · Apache Software Foundation |

Why it matters: XmlRpcServlet runs with enabledForExtensions=true, so ws-xmlrpc accepts ex:serializable. Parsing happens during HTTP handling, before XML-RPC credentials are checked. The servlet mapping remains in web.xml even when admins set webservices.enableXmlRpc=false — disabling XML-RPC in the UI does not remove this pre-auth path on 6.1.5.

PoC page: https://pocbit.org/pocs/cve-2026-82384

Bundled tool (Python 3)

Members: download poc.py from this page (View exploit code).

pip install -r requirements.txt

python poc.py -u https://blog.example.com --mode check
python poc.py -u https://blog.example.com --mode check --probe-deser
python poc.py --list targets.example.txt --mode check -j 12

python poc.py -u https://blog.example.com --mode exploit \
  --ysoserial-jar ysoserial.jar --ysoserial-gadget URLDNS \
  --ysoserial-cmd pocbit.your-oast.domain

python poc.py -u https://blog.example.com --mode exploit --payload-file chain.b64
python poc.py --list targets.txt --mode exploit -j 10 --ysoserial-jar ysoserial.jar ...

| Mode | Behavior | |------|----------| | check | Roller fingerprints, XML-RPC URL, optional --probe-deser | | exploit | Post serialized payload (file, base64, or ysoserial via --ysoserial-jar) | | Mass | --list + -j → JSONL + exploited.txt |

This PoC does not ship live RCE gadget chains (classpath-dependent). Use ysoserial or your own verified payload in authorized labs.

Attack surface

  • Content-Type: text/xml
  • Impact: RCE as Tomcat/Roller OS user; blog data and host pivot
  • Related (6.1.6): CVE-2026-82377 (XML-RPC authz), CVE-2026-82386 (XXE in bookmark import)

Remediation

  1. Upgrade to Roller 6.1.6+ immediately.
  2. Block /roller-services/xmlrpc at reverse proxy / WAF until patched.
  3. Inventory: Apache Roller, /roller-ui/, XML-RPC paths.

Hunting (examples)

body="Apache Roller"
body="/roller-ui/"
body="/roller-services/xmlrpc"

Confirm 6.1.5 from footer, about page, or release notes before treating as exploitable.

Legal and ethical use

Authorized testing only. Deserialization exploits can destroy data and violate law if misused.

References

Related PoCs

Same platform, vendor, or tags — explore more write-ups on Pocbit.

Browse full PoC archive →