CVE WATCH / VULNERABILITY DETAIL

CVE-2026-82384

CRITICALCVSS 9.8NVD feed

Published 28 September 2026 · tracked since 28 September 2026

Description

Deserialization of Untrusted Data in Apache Roller 6.1.5 allows an unauthenticated remote attacker to cause deserialization of attacker-controlled bytes, because the XML-RPC endpoint accepts vendor extension types that are deserialized during request parsing, before authentication. The servlet is ma

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-82384 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-82384

CRITICALCVSS 9.8NVD feed

Published 28 September 2026 · tracked since 28 September 2026

Description

Deserialization of Untrusted Data in Apache Roller 6.1.5 allows an unauthenticated remote attacker to cause deserialization of attacker-controlled bytes, because the XML-RPC endpoint accepts vendor extension types that are deserialized during request parsing, before authentication. The servlet is ma

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]