SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-28814

HIGH · CVSS 7.5 EPSS 0.41%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

Apache JSPWiki versions up to 2.12.3 are vulnerable to arbitrary Wiki Markup rendering due to insufficient authentication, enabling attackers to access sensitive data stored in JSPWiki variables. Organizations using affected versions should prioritize upgrading to 2.12.4 or 3.0.0 to mitigate the risk of data exposure. This vulnerability poses a significant threat to any entity relying on JSPWiki for content management, particularly those handling sensitive information.

CVE
CVE-2026-28814
Severity
HIGH
CVSS
7.5
EPSS
0.41%
Apache

Original NVD Description

Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain sensitive data stored in JSPWiki variables. Users are recommended to upgrade to version 2.12.4 or 3.0.0, which fixes this issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)