๐Ÿ” CVE Alert

CVE-2026-43975

UNKNOWN 0.0

Apache Wicket: Possible malicious path traversal in FolderUploadsFileManager

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

FolderUploadsFileManager in Apache Wicket does not validate or sanitize the uploadFieldId parameter or the clientFileName before constructing file paths, allowing an unauthenticated attacker to write arbitrary files outside the intended upload directory or read files from arbitrary locations on the server. This issue affects Apache Wicket: from 8.0.0 through 8.17.0, from 9.0.0 through 9.22.0, from 10.0.0 through 10.8.0. Users are recommended to upgrade to version 10.9.0, which fixes the issue.

CWE CWE-22
Vendor apache software foundation
Product apache wicket
Published May 6, 2026
Last Updated May 6, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache wicket

Be the first to know when new unknown vulnerabilities affecting apache software foundation apache wicket are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Apache Software Foundation / Apache Wicket
10.0.0 โ‰ค 10.8.0 9.0.0 โ‰ค 9.22.0 8.0.0 โ‰ค 8.17

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/apache/wicket/pull/1432 lists.apache.org: https://lists.apache.org/thread/xp2jrdk6ppv1zcmxb4w1mk2lg1dw3hbr openwall.com: http://www.openwall.com/lists/oss-security/2026/05/06/4