Description
Exposure of Sensitive Information to an Unauthorized Actor in Apache Roller 6.1.5 allows a weblog administrator to read files on the application classpath, including Roller configuration files containing secrets, by authoring a Velocity template that uses an include directive to load a classpath resource outside the theme namespace. Roller treats weblog administrators as untrusted and enables a Velocity sandbox, but the include and parse directives are not confined by it. No non-default configuration is required; this affects any weblog whose administrator can author templates. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which confines includes to the active theme and removes classpath resource loading from weblog rendering.
Published: 2026-09-28
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Sensitive Information Disclosure
Action: Patch Immediately
AI Analysis

Impact

A weblog administrator can author a Velocity template that uses an include directive to load a classpath resource outside the theme namespace, bypassing the Velocity sandbox. This allows the reading of application classpath files, including configuration files containing secrets. The consequence is the exposure of sensitive information through an information‑disclosure vulnerability.

Affected Systems

Apache Roller versions preceding 6.1.6, notably 6.1.5, are impacted. Any weblog whose administrator has the ability to author templates is vulnerable, regardless of additional configuration changes.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to be a weblog administrator and to author a template; no non‑default configuration is needed. The attack vector is therefore local to the web application context, relying on the presence of an privileged administrator user.

Generated by OpenCVE AI on September 28, 2026 at 09:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Roller to version 6.1.6 or later, which confines include directives to the active theme and removes classpath resource loading from weblog rendering.
  • Restrict the ability to author Velocity templates to only trusted users or disable template authoring if it is not a required feature for the service.
  • Audit existing templates for include directives that load classpath resources and remove or sanitize them; monitor application logs for anomalous include usage.

Generated by OpenCVE AI on September 28, 2026 at 09:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache roller
Vendors & Products Apache
Apache roller

Mon, 28 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
References

Mon, 28 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description Exposure of Sensitive Information to an Unauthorized Actor in Apache Roller 6.1.5 allows a weblog administrator to read files on the application classpath, including Roller configuration files containing secrets, by authoring a Velocity template that uses an include directive to load a classpath resource outside the theme namespace. Roller treats weblog administrators as untrusted and enables a Velocity sandbox, but the include and parse directives are not confined by it. No non-default configuration is required; this affects any weblog whose administrator can author templates. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which confines includes to the active theme and removes classpath resource loading from weblog rendering.
Title Apache Roller: Weblog template include escapes the Velocity sandbox and reads classpath files
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-28T08:21:47.303Z

Reserved: 2026-08-28T20:53:16.336Z

Link: CVE-2026-82385

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T08:16:42.403

Modified: 2026-09-28T09:17:06.743

Link: CVE-2026-82385

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T11:00:12Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor