CVE-2026-38165Disclosure

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A Server-Side Template Injection (SSTI) vulnerability in the Velocity template engine configuration of xdocreport v0.9.2 to v2.2.0 allows attackers to execute arbitrary code via a crafted expression.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Public PoC and exploit tooling are both present
  • 2 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-18: 2PoC Mentioned / Linked · 2026-08-18: 1Exploit Tool / Code · 2026-08-18: 1Technical Details · 2026-08-18: 208-18
Signal classification2 categories
Disclosure
150.0%
PoC
150.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Bipin Jitiya@win3zz
    PoC

    CVE-2026-38165 - SSTI to RCE in XDocReport's Velocity integration. If an application processes untrusted docx templates with XDocReport + Apache Velocity, attacker-controlled VTL can reach Java classes and execute commands in the context of the application https://gist.github.com/win3zz/34374c553effdd8fa559390883da7b86 https://t.co/Fd11nmUSMP

    Post summary

    The post announces CVE-2026-38165 as a server‑side template injection leading to remote code execution, linking to a Gist PoC that likely contains exploit code, but makes no claims of active exploitation or patches.

    016040143.0K
    7.9K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨Critical - xdocreport Velocity Template SSTI to RCE (CVE-2026-38165) xdocreport’s Velocity template engine configuration evaluates attacker-supplied template expressions; a crafted payload can escape the template context and reach Java execution primitives, leading to arbitrary code execution on the server. Deployments that only process trusted, static templates are not impacted. 👉Affected: xdocreport v0.9.2–v2.2.0

    Post summary

    The post discloses a critical SSTI vulnerability in xdocreport that can lead to arbitrary code execution, but it provides no evidence of exploits, patches, or active attacks.

    0000081
    291 followersView on X

Explore more