Vulnerability Description
UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges. Users are recommended to upgrade to version 2.12.4 or newer which fixes this issue.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Jspwiki | < 2.12.4 |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread/n3m666d6t6871dldvz3ct49ooqkbgw2pMailing ListVendor Advisory
- http://www.openwall.com/lists/oss-security/2026/07/30/15Mailing ListThird Party Advisory
FAQ
What is CVE-2026-28812?
CVE-2026-28812 is a vulnerability with a CVSS score of 9.8 (CRITICAL). UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges. Users are recommended to upgrade to version 2.12.4 or newer which fixes...
How severe is CVE-2026-28812?
CVE-2026-28812 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-28812?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Jspwiki.