SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-28812

CRITICAL · CVSS 9.8 EPSS 0.40%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

Apache JSPWiki versions up to 2.12.3 are vulnerable due to insufficient checks in the UserManager component, enabling attackers to impersonate users and potentially escalate privileges. This critical vulnerability, rated 9.8 on the CVSS scale, poses a significant risk to any organization using affected versions. Users should prioritize upgrading to version 2.12.4 or later to mitigate this security threat.

CVE
CVE-2026-28812
Severity
CRITICAL
CVSS
9.8
EPSS
0.40%
Apache

Original NVD Description

UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges. Users are recommended to upgrade to version 2.12.4 or newer which fixes this issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)