Subject: Apache Jackrabbit Security Releases: CVE-2026-92414 and CVE-2026-92415

The Apache Jackrabbit team would like to announce two security vulnerabilities affecting Apache Jackrabbit.


CVE-2026-92414 — Critical

Session Fixation / Session Reuse across Users

Jackrabbit's WebDAV server can attach a cached authenticated session based solely on a matching Lock-Token, TransactionId, SubscriptionId, or If header token, without verifying credentials. This can allow a pre-authenticated attacker to hijack or reuse cached sessions across users.

CVSS 4.0: 9.3 (Critical)

Affected versions:

* 2.23.0 through 2.23.5-beta
* 2.22.0 through 2.22.4
* 2.20.0 through 2.20.17


CVE-2026-92415 — Medium

Unsafe Reflection on WebDAV/DavEx Wire Data

A malicious WebDAV/DavEx server, or an attacker able to intercept the connection, can cause the Jackrabbit DavEx client to instantiate arbitrary classes from its classpath. This may result in arbitrary file creation or truncation.

This vulnerability affects applications using jackrabbit-spi2dav, directly or through jackrabbit-jcr2dav, to connect to a remote repository. Jackrabbit servers themselves are not affected.

CVSS 4.0: 6.9 (Medium)

The same Jackrabbit versions are affected:

* 2.23.0 through 2.23.5-beta
* 2.22.0 through 2.22.4
* 2.20.0 through 2.20.17

Users are strongly recommended to upgrade to one of the following fixed versions:

* Apache Jackrabbit 2.23.6-beta
* Apache Jackrabbit 2.22.5
* Apache Jackrabbit 2.20.18

Due to the critical severity of CVE-2026-92414, users are encouraged to prioritize upgrading.

Reply via email to