๐Ÿ” CVE Alert

CVE-2026-92414

UNKNOWN 0.0

Apache Jackrabbit: Pre-auth hijack of cached sessions via derivable WebDAV lock tokens

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

: Session Fixation / Session Reuse across Users vulnerability in Apache Jackrabbit. Jackrabbit WebDAV server attaches a cached authenticated session on any Lock-Token/TransactionId/SubscriptionId/If-header field token match with no credential check. This issue affects Apache Jackrabbit: from 2.23.0 through 2.23.5, from 2.22.0 through 2.22.4, from 2.20.0 through 2.20.17. Users are recommended to upgrade to versions 2.23.6, 2.22.5, or 2.20.18 which fix the issue.

CWE CWE-384
Vendor apache software foundation
Product apache jackrabbit
Published Oct 7, 2026
Last Updated Oct 7, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache jackrabbit

Be the first to know when new unknown vulnerabilities affecting apache software foundation apache jackrabbit are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Apache Software Foundation / Apache Jackrabbit
2.23.0 โ‰ค 2.23.5 2.22.0 โ‰ค 2.22.4 2.20.0 โ‰ค 2.20.17

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
lists.apache.org: https://lists.apache.org/thread.html/gmbsmrs2lycl9nld7rd0h1r1fc4t75qr openwall.com: http://www.openwall.com/lists/oss-security/2026/10/07/27

Credits

The Apache Software Foundation Julian Reschke Claude Security