CVE-2026-92414: Apache Jackrabbit: Pre-auth hijack of cached sessions via derivable WebDAV lock tokens
: Session Fixation / Session Reuse across Users vulnerability in Apache Jackrabbit.
Jackrabbit WebDAV server attaches a cached authenticated session on any Lock-Token/TransactionId/SubscriptionId/If-header field token match with
no credential check.
This issue affects Apache Jackrabbit: from 2.23.0 through 2.23.5, from 2.22.0 through 2.22.4, from 2.20.0 through 2.20.17.
Users are recommended to upgrade to versions 2.23.6, 2.22.5, or 2.20.18 which fix the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Jackrabbitto a version that resolves this vulnerability.Fixed in 2.23.6 - Upgrade
Upgrade
Apache Jackrabbitto a version that resolves this vulnerability.Fixed in 2.22.5 - Upgrade
Upgrade
Apache Jackrabbitto a version that resolves this vulnerability.Fixed in 2.20.18