LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-28812

apache · jspwiki

Published
CVSS9.8
Severitycritical
WeaknessCWE-290
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges. Users are recommended to upgrade to version 2.12.4 or newer which fixes this issue.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-28812

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-28812.