CVE-2026-82385: Apache Roller: Weblog template include escapes the Velocity sandbox and reads classpath files
Apache Roller 6.1.5 lets admins escape the Velocity sandbox and read classpath secrets.
Apache disclosed CVE-2026-82385 in Apache Roller 6.1.5, scored CVSS 3.1 6.5. A weblog administrator can author a Velocity template that uses an include directive to load classpath resources, bypassing the Velocity sandbox. That can expose Roller configuration files on the classpath, including secrets. The advisory does not report active exploitation.
- Affects Apache Roller 6.1.5
- Weblog admin can escape the Velocity sandbox
- Include directive reads application classpath files
- Configuration files containing secrets may be exposed
- CVSS 3.1 base score 6.5
Vulnerabilities mentionedAll →
- published —
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-82385 | NVD description · AI analysis pending | — | — | — | — | — |
Posted by David M. Johnson on Sep 25 Severity: Important CVSS 3.1: 6.5 (medium) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected versions: - Apache Roller 6.1.5 Description: Exposure of Sensitive Information to an Unauthorized Actor in Apache Roller 6.1.5 allows a weblog administrator to read files on the application classpath, including Roller configuration files containing secrets, by authoring a Velocity template that uses an include directive to load a classpath...
This source does not provide full text. Read it at seclists.org.