CVE-2026-82385: Apache Roller: Weblog template include escapes the Velocity sandbox and reads classpath files
Apache Roller 6.1.5 lets admins escape the Velocity sandbox and read classpath secrets.
Apache disclosed CVE-2026-82385 in Apache Roller 6.1.5, scored CVSS 3.1 6.5. A weblog administrator can author a Velocity template that uses an include directive to load classpath resources, bypassing the Velocity sandbox. That can expose Roller configuration files on the classpath, including secrets. The advisory does not report active exploitation.
42