CVE-2026-92414
Apache Jackrabbit: Pre-auth hijack of cached sessions via derivable WebDAV lock tokens
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
: Session Fixation / Session Reuse across Users vulnerability in Apache Jackrabbit. Jackrabbit WebDAV server attaches a cached authenticated session on any Lock-Token/TransactionId/SubscriptionId/If-header field token match with no credential check. This issue affects Apache Jackrabbit: from 2.23.0 through 2.23.5, from 2.22.0 through 2.22.4, from 2.20.0 through 2.20.17. Users are recommended to upgrade to versions 2.23.6, 2.22.5, or 2.20.18 which fix the issue.
| CWE | CWE-384 |
| Vendor | apache software foundation |
| Product | apache jackrabbit |
| Published | Oct 7, 2026 |
| Last Updated | Oct 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for apache software foundation apache jackrabbit
Be the first to know when new unknown vulnerabilities affecting apache software foundation apache jackrabbit are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Apache Software Foundation / Apache Jackrabbit
2.23.0 โค 2.23.5 2.22.0 โค 2.22.4 2.20.0 โค 2.20.17
References
Credits
The Apache Software Foundation Julian Reschke Claude Security