CVE-2026-28812: Apache JSPWiki: UserManager does not sanity-check user database at startup
UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges. Users are recommended to upgrade to version 2.12.4 or newer which fixes this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache JSPWikito a version that resolves this vulnerability.Fixed in 2.12.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28812?
CVE-2026-28812 has a risk rating of 47, indicating a significant security concern.
How do I fix CVE-2026-28812?
To fix CVE-2026-28812, users should upgrade to Apache JSPWiki version 2.12.4 or newer.
What impact does CVE-2026-28812 have on Apache JSPWiki?
CVE-2026-28812 allows for user impersonation and potential privilege escalation in Apache JSPWiki up to version 2.12.3.
Is CVE-2026-28812 present in all versions of Apache JSPWiki?
CVE-2026-28812 affects all versions of Apache JSPWiki up to and including 2.12.3.
What should I do if I cannot upgrade to fix CVE-2026-28812?
If unable to upgrade for CVE-2026-28812, users should implement additional security measures to mitigate the risk of impersonation and privilege escalation.