CVE-2026-28812 Details
Description
UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges. Users are recommended to upgrade to version 2.12.4 or newer which fixes this issue.
A vulnerability in the UserManager component of Apache JSPWiki versions prior to 2.12.3 allows for user impersonation, which could lead to unauthorized privilege escalation. This issue arises from a lack of proper validation checks in the user management process.
Users of Apache JSPWiki are advised to upgrade to version 2.12.4 or later, which addresses this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 31, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/07/30/15 | CVE | Mailing ListThird Party Advisory |
| https://lists.apache.org/thread/n3m666d6t6871dldvz3ct49ooqkbgw2p | [email protected] | Mailing ListVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-290 | Authentication Bypass by Spoofing | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| apache jspwiki | < 2.12.4 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 5, 2026 | Initial Analysis | [email protected] |
| Jul 31, 2026 | CVE Modified | CISA-ADP |
| Jul 30, 2026 | CVE Modified | CVE |
| Jul 30, 2026 | New CVE Received | [email protected] |