CVE-2026-82385: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in Apache Software Foundation Apache Roller
Exposure of Sensitive Information to an Unauthorized Actor in Apache Roller 6.1.5 allows a weblog administrator to read files on the application classpath, including Roller configuration files containing secrets, by authoring a Velocity template that uses an include directive to load a classpath resource outside the theme namespace. Roller treats weblog administrators as untrusted and enables a Velocity sandbox, but the include and parse directives are not confined by it. No non-default configuration is required; this affects any weblog whose administrator can author templates. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which confines includes to the active theme and removes classpath resource loading from weblog rendering.
AI Analysis
Technical Summary
CVE-2026-82385 is an information exposure vulnerability in Apache Roller version 6.1.5. It arises from insufficient sandboxing of Velocity template include and parse directives, allowing a weblog administrator to read arbitrary files on the application classpath, including sensitive configuration files containing secrets. The vulnerability does not require any special configuration and affects any weblog where the administrator can author templates. The issue is resolved in Apache Roller 6.1.6 and later by confining includes to the active theme and disabling classpath resource loading during weblog rendering.
Potential Impact
An attacker with weblog administrator privileges can read sensitive files on the application classpath, potentially exposing secrets such as configuration data. This could lead to information disclosure but does not directly impact integrity or availability. The vulnerability requires the attacker to have weblog administrator access, which is a limited privilege level.
Mitigation Recommendations
Users should upgrade to Apache Roller version 6.1.6 or later, which confines Velocity template includes to the active theme and removes the ability to load classpath resources during weblog rendering. This official fix addresses the vulnerability. No other configuration changes are required.
CVE-2026-82385: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in Apache Software Foundation Apache Roller
Description
Exposure of Sensitive Information to an Unauthorized Actor in Apache Roller 6.1.5 allows a weblog administrator to read files on the application classpath, including Roller configuration files containing secrets, by authoring a Velocity template that uses an include directive to load a classpath resource outside the theme namespace. Roller treats weblog administrators as untrusted and enables a Velocity sandbox, but the include and parse directives are not confined by it. No non-default configuration is required; this affects any weblog whose administrator can author templates. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which confines includes to the active theme and removes classpath resource loading from weblog rendering.
CVSS v3.1
Score 6.5medium
Affected software
Apache Software Foundation
Apache Roller
pkg:maven/org.apache.roller/rollerRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-82385 is an information exposure vulnerability in Apache Roller version 6.1.5. It arises from insufficient sandboxing of Velocity template include and parse directives, allowing a weblog administrator to read arbitrary files on the application classpath, including sensitive configuration files containing secrets. The vulnerability does not require any special configuration and affects any weblog where the administrator can author templates. The issue is resolved in Apache Roller 6.1.6 and later by confining includes to the active theme and disabling classpath resource loading during weblog rendering.
Potential Impact
An attacker with weblog administrator privileges can read sensitive files on the application classpath, potentially exposing secrets such as configuration data. This could lead to information disclosure but does not directly impact integrity or availability. The vulnerability requires the attacker to have weblog administrator access, which is a limited privilege level.
Mitigation Recommendations
Users should upgrade to Apache Roller version 6.1.6 or later, which confines Velocity template includes to the active theme and removes the ability to load classpath resources during weblog rendering. This official fix addresses the vulnerability. No other configuration changes are required.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- apache
- Date Reserved
- 2026-08-28T20:53:16.336Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aba1bc6f7a7c541065ca3d8
Added to database: 09/28/2026, 07:48:22 UTC
Last enriched: 09/28/2026, 08:03:37 UTC
Last updated: 09/29/2026, 02:51:56 UTC
Views: 18
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.