← All Advisories

CVE-2026-28814

Status: UPDATED  |  Advisory ID: CVE-2026-28814

Key Details

CVECVE-2026-28814
CVSSCVSS 7.5 (High).
Affected productsApache jspwiki
Classified asCWE-306 (Missing Authentication for Critical Function)

What to Know

Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain sensitive data stored in JSPWiki variables.

Users are recommended to upgrade to version 2.12.4 or 3.0.0, which fixes this issue.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-28814
Vendor advisoryhttps://lists.apache.org/thread/8vv0311bvrrqxsyn913pcwf7pctyk52w