PT-2026-107580 · Apache · Apache Jackrabbit

·

CVE-2026-92415

·

Published

2026-10-07

·

Updated

2026-10-07

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/S:N
Name of the Vulnerable Software and Affected Versions Apache Jackrabbit versions 2.23.0 through 2.23.5 Apache Jackrabbit versions 2.22.0 through 2.22.4 Apache Jackrabbit versions 2.20.0 through 2.20.17
Description The WebDAV/DavEx client contains a flaw where it uses externally-controlled input to select classes or code. A malicious WebDAV/DavEx server, or an attacker intercepting the connection, can force the client to instantiate arbitrary classes from its classpath by manipulating server-controlled error bodies via Class.forName. This unsafe reflection on wire data can lead to arbitrary file creation or truncation. This issue specifically affects applications using jackrabbit-spi2dav (directly or through jackrabbit-jcr2dav) to connect to remote repositories; servers are not affected.
Recommendations Upgrade Apache Jackrabbit versions 2.23.0 through 2.23.5 to version 2.23.6. Upgrade Apache Jackrabbit versions 2.22.0 through 2.22.4 to version 2.22.5. Upgrade Apache Jackrabbit versions 2.20.0 through 2.20.17 to version 2.20.18.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92415

Affected Products

Apache Jackrabbit