What is CVE-2026-28812?
CVE-2026-28812 is an impersonation vulnerability in Apache JSPWiki up to version 2.12.3, caused by a lack of checks in the UserManager component. This flaw may allow attackers to escalate their privileges. Users are recommended to upgrade to version 2.12.4 or newer, which fixes the issue.
Azərbaycanca: CVE-2026-28812, Apache JSPWiki-nin 2.12.3-ə qədər versiyalarında UserManager komponentində yoxlamaların olmaması səbəbindən imitasiya zəifliyidir. Bu boşluq mənimsəyicilərə imtiyazlarını yüksəltməyə imkan verə bilər. İstifadəçilərə problemi aradan qaldıran 2.12.4 və ya daha yeni versiyaya yüksəlmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284; shared vendor: Apache
FAQ2
Which versions of Apache JSPWiki are affected by CVE-2026-28812?
CVE-2026-28812 affects Apache JSPWiki versions up to 2.12.3.
What action should be taken to remediate CVE-2026-28812?
Users are recommended to upgrade to Apache JSPWiki version 2.12.4 or newer to fix the issue.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.