Severity Moderate Vendor The Apache Software Foundation
Versions Affected Apache JSPWiki up to 2.12.3 Description UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges. Mitigation Apache JSPWiki users should upgrade to 2.12.4 or later. Credit The issue was discovered by Florian Holeczek from Apache JSPWiki References https://jspwiki-wiki.apache.org/Wiki.jsp?page=CVE-2026-28812 https://www.cve.org/CVERecord?id=CVE-2026-28812
