CVE-2026-84939
Apache FreeMarker versions 2.2.0 through 2.3.34 have a path‑traversal flaw that lets an attacker supply a specially crafted locale identifier to load arbitrary files. The bug is triggered when the localized lookup feature is enabled, which is the default setting. Upgrading to 2.3.35 or later removes the vulnerability.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Apache FreeMarker template engine, versions 2.2.0 to 2.3.34, used in Java web and desktop applications.
Real-world impact
An attacker could read any file that the application’s template loader can access, potentially exposing configuration files, credentials, or other sensitive data on the server.
Why this severity
The CVSS score of 9.1 reflects that the flaw can be exploited over the network with no authentication, no user interaction, and it gives the attacker full confidentiality and integrity compromise of files.
What to do about it
- 01Upgrade Apache FreeMarker to version 2.3.35 or later.
- ›Disable the localized lookup feature in FreeMarker configuration.
NVD-referenced vendor advisory
Timeline
- Sep 10, 2026 · 4d agoPublishedDisclosed and added to the National Vulnerability Database.
- Sep 10, 2026 · 3d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- lists.apache.org/thread/hrd7o2ylwkkswdyhyzll…mailing listvendor advisory
- openwall.com/lists/oss-security/2026/09/…mailing listthird party advisory