Apache JSPWiki: Pre-Authentication Arbitrary Wiki Markup Rendering
Summary
| CVE | CVE-2026-28814 |
|---|---|
| State | PUBLISHED |
| Assigner | apache |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-07-30 16:17:11 UTC |
| Updated | 2026-07-30 19:33:40 UTC |
| Description | Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain sensitive data stored in JSPWiki variables. Users are recommended to upgrade to version 2.12.4 or 3.0.0, which fixes this issue. |
Risk And Classification
Problem Types: Arbitrary Wiki Markup rendering due to lack of authentication
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Apache Software Foundation | Apache JSPWiki | affected 2.12.4 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| lists.apache.org/thread/8vv0311bvrrqxsyn913pcwf7pctyk52w | [email protected] | lists.apache.org | |
| www.openwall.com/lists/oss-security/2026/07/30/17 | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Miguel Regala (Fisher) - Hadrian.io (en)
There are currently no legacy QID mappings associated with this CVE.