PT-2026-107579 · Apache · Apache Jackrabbit

·

CVE-2026-92414

·

Published

2026-10-07

·

Updated

2026-10-08

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Apache Jackrabbit versions 2.23.0 through 2.23.5 Apache Jackrabbit versions 2.22.0 through 2.22.4 Apache Jackrabbit versions 2.20.0 through 2.20.17
Description The WebDAV server allows session fixation and session reuse across users. The system attaches a cached authenticated session without performing a credential check when a match is found in the Lock-Token, TransactionId, SubscriptionId, or If-header field tokens. This can lead to a pre-authentication hijack of cached sessions via derivable WebDAV lock tokens.
Recommendations Upgrade versions 2.23.0 through 2.23.5 to 2.23.6. Upgrade versions 2.22.0 through 2.22.4 to 2.22.5. Upgrade versions 2.20.0 through 2.20.17 to 2.20.18.

Fix

Session Fixation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92414

Affected Products

Apache Jackrabbit