Information Exposure Vulnerability in Apache Roller by Apache
CVE-2026-82385

6.5MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
28 September 2026

What is CVE-2026-82385?

An information exposure vulnerability exists in Apache Roller 6.1.5, allowing weblog administrators to access sensitive files within the application classpath. By crafting a Velocity template that improperly includes a classpath resource outside the defined theme namespace, an attacker can read configuration files that may contain confidential data. Despite Roller’s implementation of a Velocity sandbox, certain directives like include and parse bypass this confinement. This vulnerability is significant as it can affect any weblog where the administrator has the ability to author templates. Users are advised to update to Apache Roller 6.1.6 or higher, which mitigates this risk by restricting includes to the active theme and eliminating classpath resource loading in rendering processes.

Affected Version(s)

Apache Roller 6.1.5

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

n0mi1k
.