CVE-2026-92414: fallo crítico en Apache Jackrabbit
Apache Jackrabbit: Pre-auth hijack of cached sessions via derivable WebDAV lock tokens
Publicada el
25Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 9.3
probabilidad de explotación
—
explotación observada
noninguna fuente lo reporta
: Session Fixation / Session Reuse across Users vulnerability in Apache Jackrabbit.
Jackrabbit WebDAV server attaches a cached authenticated session on any Lock-Token/TransactionId/SubscriptionId/If-header field token match with
no credential check.
This issue affects Apache Jackrabbit: from 2.23.0 through 2.23.5, from 2.22.0 through 2.22.4, from 2.20.0 through 2.20.17.
Users are recommended to upgrade to versions 2.23.6, 2.22.5, or 2.20.18 which fix the issue.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Productos afectados
Apache Software Foundation · Apache JackrabbitCVEs relacionadas — Apache Jackrabbit
En el mismo producto, de las más peligrosas a las menos.