{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/velocity/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-38165"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["XDocReport","Velocity"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","rce","ssti","webserver"],"_cs_type":"advisory","_cs_vendors":["OpenSAGRES","Apache"],"content_html":"\u003cp\u003eOpenSAGRES XDocReport contains a critical server-side template injection (SSTI) vulnerability, tracked as CVE-2026-38165, affecting the Apache Velocity engine integration. The flaw exists because the application fails to perform adequate input validation or filtering when rendering content from uploaded .docx files. An attacker can craft a malicious .docx document containing Velocity template expressions and upload it to an application that utilizes XDocReport for document processing. When the server processes the document, the malicious expressions are executed, leading to remote code execution (RCE) with the privileges of the web application service. This vulnerability poses a severe risk to any organization that accepts user-provided .docx files for server-side template processing, potentially resulting in full system compromise, sensitive data exfiltration, and unauthorized access to backend resources.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker identifies an application that utilizes OpenSAGRES XDocReport for processing or rendering .docx files.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious .docx document that incorporates Apache Velocity template syntax designed to execute system commands.\u003c/li\u003e\n\u003cli\u003eThe attacker navigates to the target application's file upload interface.\u003c/li\u003e\n\u003cli\u003eThe attacker uploads the weaponized .docx file to the application.\u003c/li\u003e\n\u003cli\u003eThe application triggers the XDocReport process to handle the document rendering.\u003c/li\u003e\n\u003cli\u003eThe Apache Velocity engine parses the embedded malicious template expressions without sanitization.\u003c/li\u003e\n\u003cli\u003eThe engine executes the injected expressions in the context of the server-side process, achieving remote code execution.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-38165 allows for unauthenticated remote code execution on the target server. This enables attackers to steal sensitive information, execute illegal system commands, modify or delete critical application files, and potentially gain full control over the host infrastructure. The vulnerability is rated with a CVSS score of 9.8, reflecting its high potential for total system compromise in affected environments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eIdentify all internal and external-facing applications utilizing the OpenSAGRES XDocReport library.\u003c/li\u003e\n\u003cli\u003eImplement strict file upload validation policies that reject files containing suspicious template syntax or perform sandboxed processing of user-supplied documents.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for anomalous POST requests to document upload endpoints, specifically looking for payloads containing typical Velocity or Java-related keywords.\u003c/li\u003e\n\u003cli\u003eCoordinate with vendors and developers to ensure the XDocReport library is updated to the latest secure version once a patch becomes available.\u003c/li\u003e\n\u003cli\u003eReview application service account permissions to ensure the principle of least privilege is applied, minimizing the potential impact of a successful RCE.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-29T17:47:04Z","date_published":"2026-08-29T17:47:04Z","id":"https://feed.craftedsignal.io/briefs/2026-08-38165-xdocreport-ssti/","summary":"OpenSAGRES XDocReport is vulnerable to a critical server-side template injection (SSTI) flaw via the Apache Velocity engine, allowing unauthenticated remote code execution through malicious .docx uploads.","title":"Critical RCE via Server-Side Template Injection in OpenSAGRES XDocReport","url":"https://feed.craftedsignal.io/briefs/2026-08-38165-xdocreport-ssti/"}],"language":"en","title":"CraftedSignal Threat Feed - Velocity","version":"https://jsonfeed.org/version/1.1"}