CVE-2026-28812
Last modified
CVE-2026-28812 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges. Users are recommended to upgrade to version 2.12.4 or newer which fixes this issue.. EPSS estimates a 0.31% chance of exploitation in the next 30 days.
Description
UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges. Users are recommended to upgrade to version 2.12.4 or newer which fixes this issue.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Jspwiki | < 2.12.4 |
References
- https://lists.apache.org/thread/n3m666d6t6871dldvz3ct49ooqkbgw2pMailing List, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2026/07/30/15Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-28812?
How severe is CVE-2026-28812?
How do I fix CVE-2026-28812?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-28807Improper Limitation of a Pathname to a Restricted Directory …7.5
- CVE-2026-28808Incorrect Authorization vulnerability in Erlang OTP (inets m…9.8
- CVE-2026-28809XML External Entity (XXE) vulnerability in esaml (and its fo…5.3
- CVE-2026-2881A vulnerability has been found in D-Link DWR-M960 1.01.07. T…8.8
- CVE-2026-28810Generation of Predictable Numbers or Identifiers vulnerabili…3.7
- CVE-2026-28811Debug Messages Revealing Unnecessary Information in Apache J…7.5
- CVE-2026-28813Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijackin…8.8
- CVE-2026-28814Arbitrary Wiki Markup rendering due to lack of authenticatio…7.5
- CVE-2026-28815A remote attacker can supply a short X-Wing HPKE encapsulate…7.5
- CVE-2026-28816A path handling issue was addressed with improved validation…4
- CVE-2026-28817A race condition was addressed with improved state handling.…8.1
- CVE-2026-28818A logging issue was addressed with improved data redaction. …5.3
Are you affected by CVE-2026-28812?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
