CVE-2026-28812

Summary

UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges. Users are recommended to upgrade to version 2.12.4 or newer which fixes this issue.

Affected Software

VendorProductVersion RangeStatus
Apache Software FoundationApache JSPWiki0 < 2.12.4affected

Weaknesses

  • Use of impersonation

ADP Enrichment

CVE Program Container

Additional References

References