UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges.
Users are recommended to upgrade to version 2.12.4 or newer which fixes this issue.
References
| Link | Resource |
|---|---|
| https://lists.apache.org/thread/n3m666d6t6871dldvz3ct49ooqkbgw2p | Mailing List Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2026/07/30/15 | Mailing List Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-07-30 16:17
Updated : 2026-08-05 16:50
NVD link : CVE-2026-28812
Mitre link : CVE-2026-28812
CVE.ORG link : CVE-2026-28812
JSON object : View
Products Affected
apache
- jspwiki
CWE
CWE-290
Authentication Bypass by Spoofing
