CVE-2026-61372: Apache Jena Fuseki: Web requests using SPARQL Update can escape file restrictions
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki.
This issue affects Apache Jena Fuseki: through 6.1.0.
Users are recommended to upgrade to version 6.2.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Jena Fusekito a version that resolves this vulnerability.Fixed in 6.2.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61372?
CVE-2026-61372 has a risk rating of 56.
How do I fix CVE-2026-61372?
To fix CVE-2026-61372, users should upgrade to Apache Jena Fuseki version 6.2.0 or later.
What type of vulnerability is CVE-2026-61372?
CVE-2026-61372 is a Path Traversal vulnerability affecting Apache Jena Fuseki.
Which versions of Apache Jena Fuseki are affected by CVE-2026-61372?
CVE-2026-61372 affects Apache Jena Fuseki versions up to and including 6.1.0.
What can attackers achieve with CVE-2026-61372?
Attackers can exploit CVE-2026-61372 to escape file restrictions and access unauthorized files.