<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:apache_software_foundation:apache_roller:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aapache_software_foundationapache_roller/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 28 Sep 2026 09:53:27 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aapache_software_foundationapache_roller/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unauthenticated Remote Code Execution in Apache Roller via XML-RPC Deserialization</title><link>https://feed.craftedsignal.io/briefs/2026-09-apache-roller-rce/</link><pubDate>Mon, 28 Sep 2026 09:53:27 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-apache-roller-rce/</guid><description>Apache Roller 6.1.5 is susceptible to unauthenticated remote code execution via insecure Java deserialization on the XML-RPC endpoint, which is triggered by an attacker-supplied 'ex:serializable' extension type before authentication is processed.</description><content:encoded><![CDATA[<p>Apache Roller 6.1.5 contains a critical vulnerability (CVE-2026-82384) allowing unauthenticated remote code execution (RCE) via the application's XML-RPC interface. The vulnerability resides within the <code>XmlRpcServlet</code>, which is configured with the <code>enabledForExtensions=true</code> parameter. This configuration instructs the underlying Apache ws-xmlrpc library to accept vendor-specific extensions, including <code>ex:serializable</code>, which carries base64-encoded Java serialized objects.</p>
<p>Crucially, this deserialization process occurs during the HTTP request handling phase, prior to the enforcement of authentication for Blogger or MetaWeblog APIs. Furthermore, the XML-RPC servlet mapping is active by default in the web.xml configuration, meaning even if an administrator disables XML-RPC via the application's administrative UI, the vulnerable code path remains exposed to unauthenticated exploitation. Attackers can leverage this primitive to achieve full RCE on the host server by providing a crafted gadget chain, typically generated via tools like 'ysoserial'.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>The attacker performs reconnaissance to identify Apache Roller instances by scanning for standard paths such as <code>/roller-ui/</code> or <code>/roller-services/xmlrpc</code>.</li>
<li>The attacker fingerprints the application version to confirm the target is running the vulnerable 6.1.5 release.</li>
<li>The attacker prepares a serialized Java payload using a gadget chain appropriate for the application's classpath (e.g., Commons Collections).</li>
<li>The attacker crafts an XML-RPC request using the <code>text/xml</code> content type, embedding the malicious object within an <code>ex:serializable</code> extension tag.</li>
<li>The attacker sends a POST request to <code>/roller-services/xmlrpc</code> or <code>/roller/roller-services/xmlrpc</code>.</li>
<li>The <code>XmlRpcServlet</code> parses the XML body and automatically deserializes the embedded object before reaching the authentication logic.</li>
<li>The deserialization process executes arbitrary code within the context of the JVM process.</li>
<li>The attacker achieves full control over the application's data and potentially gains a pivot point into the underlying OS.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in full unauthenticated remote code execution with the privileges of the Tomcat or Java application user. This impact includes the complete compromise of blog data, the ability to read or modify sensitive configuration files, and the potential for lateral movement within the environment. The vulnerability has been assigned a CVSS 3.1 score of 9.8, reflecting its high severity and ease of exploitation without user interaction or authentication.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the immediate upgrade of all Apache Roller instances to version 6.1.6 or later, which addresses CVE-2026-82384 by disabling extensions and tightening XML-RPC request handling. In environments where immediate patching is not possible, implement WAF or reverse proxy rules to strictly block access to the <code>/roller-services/xmlrpc</code> endpoint for all but known, authorized administrative IP addresses. Security teams should also audit their environments to identify all instances of Apache Roller by searching for common footprints such as the <code>/roller-ui/</code> directory or specific HTTP response headers.</p>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>vulnerability</category><category>rce</category><category>deserialization</category><category>apache-roller</category></item></channel></rss>