VYPR

Jackrabbit WebDAV server

by Apache

CVEs (1)

  • CVE-2026-92414CriOct 7, 2026
    risk 0.60cvss —epss —

    : Session Fixation / Session Reuse across Users vulnerability in Apache Jackrabbit. Jackrabbit WebDAV server attaches a cached authenticated session on any Lock-Token/TransactionId/SubscriptionId/If-header field token match with no credential check. This issue affects…