CVE-2026-82384 is a deserialization-of-untrusted-data vulnerability in Apache Roller 6.1.5. Its XML-RPC endpoint accepts vendor extension types containing attacker-controlled bytes and deserializes them during request parsing before authentication. The XML-RPC servlet is mapped unconditionally, leaving the parsing path reachable even when XML-RPC is globally disabled. Successful exploitation can result in remote code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
The repository contains a single Python 3 entry point, poc.py, plus documentation, dependencies, and an example target list. The script is a network/web exploit and scanner for the claimed Apache Roller 6.1.5 XML-RPC deserialization issue (CVE-2026-82384). It normalizes target URLs, identifies Roller from response markers and version strings, tests several XML-RPC servlet paths, and optionally sends a minimal invalid Java serialization stream to elicit deserialization errors. Exploit mode wraps externally supplied or locally ysoserial-generated Java serialized bytes in an XML-RPC ex:serializable element and submits it to the discovered endpoint. It supports individual and concurrent list-based operation, HTTP proxying, disabled TLS verification, JSONL reporting, and separate hit/exploited target lists. No live gadget chain is embedded; exploitation success depends on an operator-provided payload and compatible target-side Java libraries.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical unauthenticated remote code-execution vulnerability in Apache Roller 6.1.5. Its XML-RPC endpoint deserializes attacker-controlled vendor extension types before authentication, including when XML-RPC is globally disabled because the servlet mapping remains unconditional.
Critical unauthenticated remote code execution vulnerability in Apache Roller 6.1.5. Its XML-RPC endpoint deserializes attacker-controlled vendor extension types before authentication, and this parsing occurs even when the global XML-RPC feature is disabled because the servlet remains unconditionally mapped.
A critical unauthenticated remote deserialization vulnerability in Apache Roller 6.1.5's XML-RPC endpoint. Attacker-controlled vendor extension types are deserialized before authentication, including when XML-RPC is globally disabled, potentially enabling remote code execution.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.