9.8
CVE-2026-28812
- EPSS 0.4%
- Veröffentlicht 30.07.2026 16:17:10
- Zuletzt bearbeitet 05.08.2026 16:50:37
- Erkennungen
Apache JSPWiki: UserManager does not sanity-check user database at startup
UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges. Users are recommended to upgrade to version 2.12.4 or newer which fixes this issue.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.4% | 0.331 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-290 Authentication Bypass by Spoofing
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
https://lists.apache.org/thread/n3m666d6t6871dldvz3ct49ooqkbgw2p
http://www.openwall.com/lists/oss-security/2026/07/30/15