7.5
CVE-2026-28814
- EPSS 0.41%
- Veröffentlicht 30.07.2026 16:17:11
- Zuletzt bearbeitet 05.08.2026 16:49:44
- Erkennungen
Apache JSPWiki: Pre-Authentication Arbitrary Wiki Markup Rendering
Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain sensitive data stored in JSPWiki variables. Users are recommended to upgrade to version 2.12.4 or 3.0.0, which fixes this issue.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.41% | 0.338 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-306 Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
https://lists.apache.org/thread/8vv0311bvrrqxsyn913pcwf7pctyk52w
http://www.openwall.com/lists/oss-security/2026/07/30/17