What is CVE-2026-66391?
CVE-2026-66391 is a vulnerability in Apache Wicket involving insufficiently random values leading to a protection mechanism failure. It affects versions 9.0.0 through 9.23.0 and 10.0.0 through 10.9.0; users are advised to upgrade to version 10.10.0 immediately.
Azərbaycanca: CVE-2026-66391 Apache Wicket-də kifayət qədər təsadüfi olmayan dəyərlərin istifadəsi səbəbindən mühafizə mexanizminin sıradan çıxması zəifliyidir. Bu problem 9.0.0-9.23.0 və 10.0.0-10.9.0 versiyalarına təsir edir; istifadəçilərə dərhal 10.10.0 versiyasına yeniləmə tövsiyə olunur.
Related CVEs
link basis: shared vendor: Apache
FAQ2
Which versions of Apache Wicket are affected by CVE-2026-66391?
This vulnerability affects Apache Wicket versions 9.0.0 through 9.23.0 and 10.0.0 through 10.9.0.
What action should be taken to address CVE-2026-66391?
Users are advised to upgrade to Apache Wicket version 10.10.0 immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.