Skip to content
Rota Nacional

Cyber ·

Apache Roller 6.1.5: flaw may expose classpath files

A notice published on September 25, 2026 says a weblog administrator can use an include directive in a Velocity template to read classpath files, including configurations containing secrets.

The notice for CVE-2026-82385 describes a flaw in Apache Roller 6.1.5: a weblog administrator can create a Velocity template with an include directive to read application classpath files, including Roller configuration files containing secrets. The publication rates the severity as important and gives a CVSS 3.1 score of 6.5, with vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N. The affected version listed is 6.1.5.

The text is an automatic translation of a post in the oss-sec feed, dated September 25, 2026. To check the report and any updates, consult the original entry in the oss-sec feed archive and compare the version, vector, and description; do not assume the notice specifies a fix or additional affected versions. If you use AI to analyze the material, do not submit configurations, secrets, or other internal data without first applying your organization’s data protection policy.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free