Apache Roller 6.1.5: flaw may expose classpath files
A notice published on September 25, 2026 says a weblog administrator can use an include directive in a Velocity template to read classpath files, including configurations containing secrets.
The notice for CVE-2026-82385 describes a flaw in Apache Roller 6.1.5: a weblog administrator can create a Velocity template with an include directive to read application classpath files, including Roller configuration files containing secrets. The publication rates the severity as important and gives a CVSS 3.1 score of 6.5, with vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N. The affected version listed is 6.1.5.
The text is an automatic translation of a post in the oss-sec feed, dated September 25, 2026. To check the report and any updates, consult the original entry in the oss-sec feed archive and compare the version, vector, and description; do not assume the notice specifies a fix or additional affected versions. If you use AI to analyze the material, do not submit configurations, secrets, or other internal data without first applying your organization’s data protection policy.