CVE-2026-76985
Last modified
CVE-2026-76985 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.extensions.markup.html.form.palette.component.AbstractOptions, which renders the two option lists of a Palette, escapes the id and the display value of each option according to the escape-model-strings setting, and wrote the attribute names and values returned by getAdditionalAttributes into the <option> tag as they came. An application is affected where it overrides Palette.getAdditionalAttributesForChoices, Palette.getAdditionalAttributesForSelection or AbstractOptions.getAdditionalAttributes and returns a value holding data an attacker can influence. These methods return null by default, so an application that does not override them is not affected. As a workaround, escape the values in the override. This issue affects Apache Wicket: from 8.0.0 through 8.18.0, from 9.0.0 through 9.23.0, from 10.0.0 through 10.10.0. EPSS estimates a 0.41% chance of exploitation in the next 30 days.
Description
Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.extensions.markup.html.form.palette.component.AbstractOptions, which renders the two option lists of a Palette, escapes the id and the display value of each option according to the escape-model-strings setting, and wrote the attribute names and values returned by getAdditionalAttributes into the <option> tag as they came. An application is affected where it overrides Palette.getAdditionalAttributesForChoices, Palette.getAdditionalAttributesForSelection or AbstractOptions.getAdditionalAttributes and returns a value holding data an attacker can influence. These methods return null by default, so an application that does not override them is not affected. As a workaround, escape the values in the override. This issue affects Apache Wicket: from 8.0.0 through 8.18.0, from 9.0.0 through 9.23.0, from 10.0.0 through 10.10.0. Older, unsupported releases from 1.4.0 onwards are also affected. Users are recommended to upgrade to version 8.19.0, 9.24.0 or 10.11.0, which fix the issue.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Wicket | >= 8.0.0, < 8.19.0 |
| Apache | Wicket | >= 9.0.0, < 9.24.0 |
| Apache | Wicket | >= 10.0.0, < 10.11.0 |
References
- https://lists.apache.org/thread/0x2x12x22ff4yq4rhqokb2fjhtsd0f0jVendor Advisory, Mailing List
- https://www.openwall.com/lists/oss-security/2026/08/31/5Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-76985?
How severe is CVE-2026-76985?
How do I fix CVE-2026-76985?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-76974SAP Fiori Launchpad does not sufficiently validate certain u…5.3
- CVE-2026-76977SAP UI5 does not sufficiently validate the parent frame's or…4.3
- CVE-2026-7698A vulnerability was identified in Tiandy Easy7 Integrated Ma…7.3
- CVE-2026-76982Improper neutralization of input during web page generation …5.4
- CVE-2026-76983Improper neutralization of input during web page generation …5.4
- CVE-2026-76984Improper neutralization of input during web page generation …5.4
- CVE-2026-76986Improper neutralization of input during web page generation …6.1
- CVE-2026-76987A security flaw has been discovered in liftoff-sr CIPster 18…7.3
- CVE-2026-76988A weakness has been identified in liftoff-sr CIPster 1802525…5.3
- CVE-2026-76989A security vulnerability has been detected in liftoff-sr CIP…5.3
- CVE-2026-7699A security flaw has been discovered in Dromara MaxKey up to …6.3
- CVE-2026-76990A vulnerability has been found in code-projects Simple Inven…7.3
Are you affected by CVE-2026-76985?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
