Unrated severityNVD Advisory· Published Jul 30, 2026· Updated Jul 31, 2026
Apache JSPWiki: UserManager does not sanity-check user database at startup
CVE-2026-28812
Description
UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges. Users are recommended to upgrade to version 2.12.4 or newer which fixes this issue.
Affected products
1Patches
Vulnerability mechanics
References
1- lists.apache.org/thread/n3m666d6t6871dldvz3ct49ooqkbgw2pmitrevendor-advisory
News mentions
0No linked articles in our index yet.