Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain sensitive data stored in JSPWiki variables.
Users are recommended to upgrade to version 2.12.4 or 3.0.0, which fixes this issue.
References
| Link | Resource |
|---|---|
| https://lists.apache.org/thread/8vv0311bvrrqxsyn913pcwf7pctyk52w | Mailing List Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2026/07/30/17 | Mailing List Third Party Advisory |
Configurations
History
05 Aug 2026, 16:49
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Apache
Apache jspwiki |
|
| CPE | cpe:2.3:a:apache:jspwiki:*:*:*:*:*:*:*:* | |
| References | () https://lists.apache.org/thread/8vv0311bvrrqxsyn913pcwf7pctyk52w - Mailing List, Vendor Advisory | |
| References | () http://www.openwall.com/lists/oss-security/2026/07/30/17 - Mailing List, Third Party Advisory |
31 Jul 2026, 18:17
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| CWE | CWE-306 |
30 Jul 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
30 Jul 2026, 16:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-30 16:17
Updated : 2026-08-05 16:49
NVD link : CVE-2026-28814
Mitre link : CVE-2026-28814
CVE.ORG link : CVE-2026-28814
JSON object : View
Products Affected
apache
- jspwiki
CWE
CWE-306
Missing Authentication for Critical Function
