Information Exposure Vulnerability in Apache Roller by Apache
CVE-2026-82385
What is CVE-2026-82385?
An information exposure vulnerability exists in Apache Roller 6.1.5, allowing weblog administrators to access sensitive files within the application classpath. By crafting a Velocity template that improperly includes a classpath resource outside the defined theme namespace, an attacker can read configuration files that may contain confidential data. Despite Roller’s implementation of a Velocity sandbox, certain directives like include and parse bypass this confinement. This vulnerability is significant as it can affect any weblog where the administrator has the ability to author templates. Users are advised to update to Apache Roller 6.1.6 or higher, which mitigates this risk by restricting includes to the active theme and eliminating classpath resource loading in rendering processes.
Affected Version(s)
Apache Roller 6.1.5