{"api_version":"1","generated_at":"2026-07-30T20:40:02+00:00","cve":"CVE-2026-28814","urls":{"html":"https://cve.report/CVE-2026-28814","api":"https://cve.report/api/cve/CVE-2026-28814.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-28814","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-28814"},"summary":{"title":"Apache JSPWiki: Pre-Authentication Arbitrary Wiki Markup Rendering","description":"Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain sensitive data stored in JSPWiki variables.\nUsers are recommended to upgrade to version 2.12.4 or 3.0.0, which fixes this issue.","state":"PUBLISHED","assigner":"apache","published_at":"2026-07-30 16:17:11","updated_at":"2026-07-30 19:33:40"},"problem_types":["Arbitrary Wiki Markup rendering due to lack of authentication"],"metrics":[],"references":[{"url":"https://lists.apache.org/thread/8vv0311bvrrqxsyn913pcwf7pctyk52w","name":"https://lists.apache.org/thread/8vv0311bvrrqxsyn913pcwf7pctyk52w","refsource":"security@apache.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"http://www.openwall.com/lists/oss-security/2026/07/30/17","name":"http://www.openwall.com/lists/oss-security/2026/07/30/17","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-28814","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-28814","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Apache Software Foundation","product":"Apache JSPWiki","version":"affected 2.12.4 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Miguel Regala (Fisher) - Hadrian.io","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2026-07-30T16:36:36.963Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"url":"http://www.openwall.com/lists/oss-security/2026/07/30/17"}],"title":"CVE Program Container"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"Apache JSPWiki","vendor":"Apache Software Foundation","versions":[{"lessThan":"2.12.4","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Miguel Regala (Fisher) - Hadrian.io"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain sensitive data stored in JSPWiki variables.<br>Users are recommended to upgrade to version 2.12.4 or 3.0.0, which fixes this issue."}],"value":"Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain sensitive data stored in JSPWiki variables.\nUsers are recommended to upgrade to version 2.12.4 or 3.0.0, which fixes this issue."}],"metrics":[{"other":{"content":{"text":"critical"},"type":"Textual description of severity"}}],"problemTypes":[{"descriptions":[{"description":"Arbitrary Wiki Markup rendering due to lack of authentication","lang":"en"}]}],"providerMetadata":{"dateUpdated":"2026-07-30T15:55:28.034Z","orgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","shortName":"apache"},"references":[{"tags":["vendor-advisory"],"url":"https://lists.apache.org/thread/8vv0311bvrrqxsyn913pcwf7pctyk52w"}],"source":{"defect":["JSPWIKI-1270"],"discovery":"UNKNOWN"},"title":"Apache JSPWiki: Pre-Authentication Arbitrary Wiki Markup Rendering","x_generator":{"engine":"Vulnogram 0.2.0"}}},"cveMetadata":{"assignerOrgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","assignerShortName":"apache","cveId":"CVE-2026-28814","datePublished":"2026-07-30T15:55:28.034Z","dateReserved":"2026-03-03T15:02:10.764Z","dateUpdated":"2026-07-30T16:36:36.963Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-07-30 16:17:11","lastModifiedDate":"2026-07-30 19:33:40","problem_types":["Arbitrary Wiki Markup rendering due to lack of authentication"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"28814","Ordinal":"1","Title":"Apache JSPWiki: Pre-Authentication Arbitrary Wiki Markup Renderi","CVE":"CVE-2026-28814","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"28814","Ordinal":"1","NoteData":"Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain sensitive data stored in JSPWiki variables.\nUsers are recommended to upgrade to version 2.12.4 or 3.0.0, which fixes this issue.","Type":"Description","Title":"Apache JSPWiki: Pre-Authentication Arbitrary Wiki Markup Renderi"}]}}}