CVE-2026-28814: Apache JSPWiki: Pre-Authentication Arbitrary Wiki Markup Rendering
Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain sensitive data stored in JSPWiki variables. Users are recommended to upgrade to version 2.12.4 or 3.0.0, which fixes this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache JSPWikito a version that resolves this vulnerability.Fixed in 2.12.4 - Upgrade
Upgrade
Apache JSPWikito a version that resolves this vulnerability.Fixed in 3.0.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28814?
The severity of CVE-2026-28814 is rated at 55.
What impact does CVE-2026-28814 have on Apache JSPWiki?
CVE-2026-28814 allows for pre-authentication arbitrary wiki markup rendering, potentially exposing sensitive data.
How do I fix CVE-2026-28814?
To fix CVE-2026-28814, it is recommended to upgrade Apache JSPWiki to version 2.12.4 or 3.0.0.
Which versions of Apache JSPWiki are affected by CVE-2026-28814?
Apache JSPWiki versions up to and including 2.12.3 are affected by CVE-2026-28814.
Can CVE-2026-28814 be exploited remotely?
Yes, CVE-2026-28814 can be exploited remotely due to lack of authentication.