Sceawere

Vulnerability Detail

CVE-2026-82385UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Apache Roller Path Traversal Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
4h ago
Vendor
Apache Software Foundation
Product
Apache Roller
Attack Type
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Exposure of Sensitive Information to an Unauthorized Actor in Apache Roller 6.1.5 allows a weblog administrator to read files on the application classpath, including Roller configuration files containing secrets, by authoring a Velocity template that uses an include directive to load a classpath resource outside the theme namespace. Roller treats weblog administrators as untrusted and enables a Velocity sandbox, but the include and parse directives are not confined by it. No non-default configuration is required; this affects any weblog whose administrator can author templates. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which confines includes to the active theme and removes classpath resource loading from weblog rendering.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-09-28T08:16:42.403Z",
  "pubdate": "2026-09-28T08:16:42.403Z",
  "executiveSummary": "This vulnerability is an Exposure of Sensitive Information to an Unauthorized Actor within Apache Roller 6.1.5.\nThe flaw allows authenticated weblog administrators to bypass intended security constraints to read arbitrary files located on the application classpath.\nThe vulnerability stems from the improper implementation of Velocity template directives, specifically 'include' and 'parse', which fail to adhere to the configured Velocity sandbox constraints.\nBy crafting a malicious Velocity template, an attacker can extract sensitive system configuration files containing secrets, posing a critical risk to the confidentiality and integrity of the application environment.\nThe exploitation requires the attacker to possess weblog administrator privileges; however, no non-default configurations are necessary, as the flaw exists within the core template rendering engine.\nThis issue exposes critical infrastructure secrets to untrusted administrative users, potentially leading to full system compromise if credentials or keys are successfully exfiltrated.",
  "technicalDetails": "The root cause of this vulnerability lies in an insufficient restriction of the Velocity template engine's directive processing within Apache Roller 6.1.5.\nWhile Apache Roller employs a Velocity sandbox to isolate weblog administrators—who are designated as untrusted users—the sandbox mechanism fails to restrict the 'include' and 'parse' directives during the template rendering process.\nThese directives are designed to load and process template fragments; however, they do not enforce namespace isolation, allowing an attacker to reference resources located on the application classpath that fall outside the authorized theme directory.\nThe attack flow proceeds as follows: First, an authenticated weblog administrator accesses the template authoring interface. Second, the attacker crafts a malicious template using the 'include' directive, specifying a path to a sensitive file on the application classpath (e.g., configuration files containing database credentials or API keys). Third, when the weblog is rendered, the Apache Roller application executes the directive, resolving the path against the classpath instead of restricting it to the active theme.\nThe application subsequently reads the requested file content and renders it within the output of the weblog page, effectively exfiltrating the sensitive content to the attacker.\nThe vulnerable component is the Velocity template rendering engine integrated within Apache Roller. The exploitation is trivial once administrative access is obtained, as it does not require external network exposure beyond the standard web interface of the application.\nPost-exploitation, an attacker can access system-level secrets stored in configuration files. These secrets often provide the necessary credentials to escalate privileges, access backend databases, or perform unauthorized interactions with integrated services, leading to a complete compromise of the Apache Roller installation."
}
CVE-2026-82385: Apache Roller Path Traversal Vulnerability (MEDIUM Severity, CVSS: 6.5) | Sceawere