A notice published on September 25, 2026 reports unauthenticated deserialization in Apache Roller 6.1.5's XML-RPC endpoint and rates the flaw critical, with a CVSS 3.1 score of 9.8.
A notice in the oss-sec feed, published on September 25, 2026, reports a flaw in Apache Roller 6.1.5. According to the text, the XML-RPC endpoint accepts vendor extension types and deserializes attacker-controlled data before authentication. The flaw is identified as CVE-2026-82384 and has a CVSS 3.1 score of 9.8, rated critical.
The notice lists version 6.1.5 as affected and indicates potential impacts on confidentiality, integrity, and availability. To confirm the scope, consult the original notice in the oss-sec archive and compare its details with official Apache Roller advisories; do not assume that versions or fixes not mentioned in the text are covered. If you use AI to analyze the notice or plan a response, do not submit credentials or personal data, and follow your organization's data-protection policy.