{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/apache-roller-6.1.5/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:apache_software_foundation:apache_roller:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-82384"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Apache Roller (6.1.5)"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","rce","deserialization","apache-roller"],"_cs_type":"advisory","_cs_vendors":["Apache Software Foundation"],"content_html":"\u003cp\u003eApache Roller 6.1.5 contains a critical vulnerability (CVE-2026-82384) allowing unauthenticated remote code execution (RCE) via the application's XML-RPC interface. The vulnerability resides within the \u003ccode\u003eXmlRpcServlet\u003c/code\u003e, which is configured with the \u003ccode\u003eenabledForExtensions=true\u003c/code\u003e parameter. This configuration instructs the underlying Apache ws-xmlrpc library to accept vendor-specific extensions, including \u003ccode\u003eex:serializable\u003c/code\u003e, which carries base64-encoded Java serialized objects.\u003c/p\u003e\n\u003cp\u003eCrucially, this deserialization process occurs during the HTTP request handling phase, prior to the enforcement of authentication for Blogger or MetaWeblog APIs. Furthermore, the XML-RPC servlet mapping is active by default in the web.xml configuration, meaning even if an administrator disables XML-RPC via the application's administrative UI, the vulnerable code path remains exposed to unauthenticated exploitation. Attackers can leverage this primitive to achieve full RCE on the host server by providing a crafted gadget chain, typically generated via tools like 'ysoserial'.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker performs reconnaissance to identify Apache Roller instances by scanning for standard paths such as \u003ccode\u003e/roller-ui/\u003c/code\u003e or \u003ccode\u003e/roller-services/xmlrpc\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe attacker fingerprints the application version to confirm the target is running the vulnerable 6.1.5 release.\u003c/li\u003e\n\u003cli\u003eThe attacker prepares a serialized Java payload using a gadget chain appropriate for the application's classpath (e.g., Commons Collections).\u003c/li\u003e\n\u003cli\u003eThe attacker crafts an XML-RPC request using the \u003ccode\u003etext/xml\u003c/code\u003e content type, embedding the malicious object within an \u003ccode\u003eex:serializable\u003c/code\u003e extension tag.\u003c/li\u003e\n\u003cli\u003eThe attacker sends a POST request to \u003ccode\u003e/roller-services/xmlrpc\u003c/code\u003e or \u003ccode\u003e/roller/roller-services/xmlrpc\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003eXmlRpcServlet\u003c/code\u003e parses the XML body and automatically deserializes the embedded object before reaching the authentication logic.\u003c/li\u003e\n\u003cli\u003eThe deserialization process executes arbitrary code within the context of the JVM process.\u003c/li\u003e\n\u003cli\u003eThe attacker achieves full control over the application's data and potentially gains a pivot point into the underlying OS.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full unauthenticated remote code execution with the privileges of the Tomcat or Java application user. This impact includes the complete compromise of blog data, the ability to read or modify sensitive configuration files, and the potential for lateral movement within the environment. The vulnerability has been assigned a CVSS 3.1 score of 9.8, reflecting its high severity and ease of exploitation without user interaction or authentication.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the immediate upgrade of all Apache Roller instances to version 6.1.6 or later, which addresses CVE-2026-82384 by disabling extensions and tightening XML-RPC request handling. In environments where immediate patching is not possible, implement WAF or reverse proxy rules to strictly block access to the \u003ccode\u003e/roller-services/xmlrpc\u003c/code\u003e endpoint for all but known, authorized administrative IP addresses. Security teams should also audit their environments to identify all instances of Apache Roller by searching for common footprints such as the \u003ccode\u003e/roller-ui/\u003c/code\u003e directory or specific HTTP response headers.\u003c/p\u003e\n","date_modified":"2026-09-28T09:53:27Z","date_published":"2026-09-28T09:53:27Z","id":"https://feed.craftedsignal.io/briefs/2026-09-apache-roller-rce/","summary":"Apache Roller 6.1.5 is susceptible to unauthenticated remote code execution via insecure Java deserialization on the XML-RPC endpoint, which is triggered by an attacker-supplied 'ex:serializable' extension type before authentication is processed.","title":"Unauthenticated Remote Code Execution in Apache Roller via XML-RPC Deserialization","url":"https://feed.craftedsignal.io/briefs/2026-09-apache-roller-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Apache Roller (6.1.5)","version":"https://jsonfeed.org/version/1.1"}