https://seclists.org/oss-sec/2026/q3/284: CVE-2026-66390: Apache Wicket: crafted Link URL strings can bak out of the JavaScript sequence
Published Jul 27, 2026
·Updated
Affected Software
2 affected components
Apache wicket>=9.0.0<=9.23.0, >=10.0.0<=10.9.0
Apache Apache Wicket>=9.0.0<=9.23.0, >=10.0.0<=10.9.0
Frequently Asked Questions
1
What is the severity of CVE-2026-66390?
The severity of CVE-2026-66390 is classified as important.
2
Which Apache Wicket versions are affected by CVE-2026-66390?
CVE-2026-66390 affects Apache Wicket versions from 9.0.0 through 9.23.0 and 10.0.0 through 10.9.0.
3
What type of vulnerability is CVE-2026-66390?
CVE-2026-66390 is a Cross-site Scripting (XSS) vulnerability caused by improper neutralization of input during web page generation.
4
How do I fix CVE-2026-66390 in my application?
To fix CVE-2026-66390, upgrade Apache Wicket to a version that is not affected, such as above 10.9.0.
5
What are the potential impacts of exploiting CVE-2026-66390?
Exploiting CVE-2026-66390 can allow attackers to execute arbitrary JavaScript in the context of the user's browser.