← All Advisories

CVE-2026-28812

Status: UPDATED  |  Advisory ID: CVE-2026-28812

Key Details

CVECVE-2026-28812
CVSSCVSS 9.8 (Critical).
Affected productsApache jspwiki
Classified asCWE-290 (Authentication Bypass by Spoofing)

What to Know

UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges.

Users are recommended to upgrade to version 2.12.4 or newer which fixes this issue.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-28812
Vendor advisoryhttps://lists.apache.org/thread/n3m666d6t6871dldvz3ct49ooqkbgw2p