ZeroHour

CVE-2026-28812

CVSS 3.1
9.8 critical
EPSS
<1%p34
Published
()
Modified
Description

UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges. Users are recommended to upgrade to version 2.12.4 or newer which fixes this issue.

Vendors
apache
Products
jspwiki
Weakness
CWE-290
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.