{"api_version":"1","generated_at":"2026-07-30T20:38:17+00:00","cve":"CVE-2026-28812","urls":{"html":"https://cve.report/CVE-2026-28812","api":"https://cve.report/api/cve/CVE-2026-28812.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-28812","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-28812"},"summary":{"title":"Apache JSPWiki: UserManager does not sanity-check user database at startup","description":"UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges.\nUsers are recommended to upgrade to version 2.12.4 or newer which fixes this issue.","state":"PUBLISHED","assigner":"apache","published_at":"2026-07-30 16:17:10","updated_at":"2026-07-30 19:33:40"},"problem_types":["Use of impersonation"],"metrics":[],"references":[{"url":"https://lists.apache.org/thread/n3m666d6t6871dldvz3ct49ooqkbgw2p","name":"https://lists.apache.org/thread/n3m666d6t6871dldvz3ct49ooqkbgw2p","refsource":"security@apache.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"http://www.openwall.com/lists/oss-security/2026/07/30/15","name":"http://www.openwall.com/lists/oss-security/2026/07/30/15","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-28812","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-28812","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Apache Software Foundation","product":"Apache JSPWiki","version":"affected 2.12.4 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Florian Holeczek from Apache JSPWiki","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2026-07-30T16:36:31.861Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"url":"http://www.openwall.com/lists/oss-security/2026/07/30/15"}],"title":"CVE Program Container"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"Apache JSPWiki","vendor":"Apache Software Foundation","versions":[{"lessThan":"2.12.4","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Florian Holeczek from Apache JSPWiki"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges.<br>Users are recommended to upgrade to version 2.12.4 or newer which fixes this issue."}],"value":"UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges.\nUsers are recommended to upgrade to version 2.12.4 or newer which fixes this issue."}],"metrics":[{"other":{"content":{"text":"moderate"},"type":"Textual description of severity"}}],"problemTypes":[{"descriptions":[{"description":"Use of impersonation","lang":"en"}]}],"providerMetadata":{"dateUpdated":"2026-07-30T15:52:34.172Z","orgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","shortName":"apache"},"references":[{"tags":["vendor-advisory"],"url":"https://lists.apache.org/thread/n3m666d6t6871dldvz3ct49ooqkbgw2p"}],"source":{"defect":["JSPWIKI-130"],"discovery":"UNKNOWN"},"title":"Apache JSPWiki: UserManager does not sanity-check user database at startup","x_generator":{"engine":"Vulnogram 0.2.0"}}},"cveMetadata":{"assignerOrgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","assignerShortName":"apache","cveId":"CVE-2026-28812","datePublished":"2026-07-30T15:52:34.172Z","dateReserved":"2026-03-03T15:01:12.543Z","dateUpdated":"2026-07-30T16:36:31.861Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-07-30 16:17:10","lastModifiedDate":"2026-07-30 19:33:40","problem_types":["Use of impersonation"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"28812","Ordinal":"1","Title":"Apache JSPWiki: UserManager does not sanity-check user database ","CVE":"CVE-2026-28812","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"28812","Ordinal":"1","NoteData":"UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges.\nUsers are recommended to upgrade to version 2.12.4 or newer which fixes this issue.","Type":"Description","Title":"Apache JSPWiki: UserManager does not sanity-check user database "}]}}}