← Browse

CVE-2026-28812

Medium

Elevated severity or exploit probability.

CVSS base
9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS — probability of exploitation (30 days)
0.7%
50.7th percentile
CISA KEV
Not listed
Weakness / dates
CWE-290
Published 2026-07-30 · modified 2026-08-05

Description

UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges. Users are recommended to upgrade to version 2.12.4 or newer which fixes this issue.

Affected

apache

References

Official: NVD · CVE.org