CVE-2026-28814

Summary

Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain sensitive data stored in JSPWiki variables. Users are recommended to upgrade to version 2.12.4 or 3.0.0, which fixes this issue.

Affected Software

VendorProductVersion RangeStatus
Apache Software FoundationApache JSPWiki0 < 2.12.4affected

Weaknesses

  • Arbitrary Wiki Markup rendering due to lack of authentication

ADP Enrichment

CVE Program Container

Additional References

References