Path Traversal Vulnerability in Apache FreeMarker Template Engine
CVE-2026-84939

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
10 September 2026

What is CVE-2026-84939?

A path traversal vulnerability exists in the Apache FreeMarker template loading mechanism. This occurs if an attacker can supply a malformed locale identifier while the localized lookup setting is enabled, which is the default configuration. Affected versions include FreeMarker from 2.2.0 through 2.3.34. It is recommended to upgrade to version 2.3.35 or disable the localized lookup setting in previous versions to mitigate this risk. While the files loaded are generally restricted by the TemplateLoader configuration, some loaders may permit access outside of their specified base directory, emphasizing the need for prompt action.

Affected Version(s)

Apache FreeMarker 2.2.0 <= 2.3.34

Apache FreeMarker 2.2.0 <= 2.3.34

Apache FreeMarker 2.3.35

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.