CVE-2026-84939
Analyzed Analyzed - Analysis Complete

Path Traversal in Apache FreeMarker Template Engine

Vulnerability report for CVE-2026-84939, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-10

Last updated on: 2026-09-11

Assigner: Apache Software Foundation

Description

Path traversal vulnerability in Apache FreeMarker template loading mechanism, if the attacker can specify an arbitrary malformed locale identifier to FreeMarker, and the localized lookup configuration setting is enabled (it's by default enabled). This issue affects Apache FreeMarker from 2.2.0 through 2.3.34. Users are recommended to upgrade to version 2.3.35. Disabling localized lookup in previous versions also mitigates this. Note that even in versions affected by this vulnerability, the files that can be loaded remain restricted by the TemplateLoader that FreeMarker is configured to use. In particular, FileTemplateLoader prevents attempts to traverse outside the baseDir specified in its constructor. Other TemplateLoader implementations may allow access outside their designated base directory, but they are still constrained by the underlying storage mechanismβ€”for example, a loader wrapping a Java class loader can only access resources that the class loader can load, while one wrapping a web application context can only access resources available through that context.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-10
Last Modified
2026-09-11
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
apache freemarker From 2.2 (inc) to 2.3.35 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-23 The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a path traversal vulnerability in Apache FreeMarker where an attacker can specify a malformed locale identifier to access files outside the intended directory. It affects versions 2.2.0 through 2.3.34 and occurs when localized lookup is enabled, which is the default setting.

Detection Guidance

Detecting this vulnerability requires checking the Apache FreeMarker version and configuration. Run: java -jar freemarker.jar --version to check the version. If using 2.2.0 through 2.3.34, the system is vulnerable. Also verify if localized lookup is enabled in the configuration files.

Impact Analysis

An attacker could exploit this to read sensitive files outside the intended directory structure, potentially exposing confidential data. The impact depends on the TemplateLoader configuration, which may restrict or allow broader access.

Compliance Impact

This vulnerability could potentially lead to unauthorized file access, which may result in exposure of sensitive data. For GDPR, this could violate principles of data protection and confidentiality. For HIPAA, unauthorized access to protected health information could lead to compliance violations. The impact depends on the data accessed and organizational safeguards.

Mitigation Strategies

Upgrade Apache FreeMarker to version 2.3.35. If upgrading is not possible, disable localized lookup in the configuration. Ensure TemplateLoader settings restrict file access to intended directories to limit exposure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84939. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart