Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-92414: Apache Jackrabbit may let attackers hijack user sessions
CVE-2026-92414 · published 2 days ago
Summary
The Jackrabbit content repository used in your web applications can mistakenly accept an existing authenticated session when certain request headers match, allowing one user to take over another's session. This can expose sensitive data or let an attacker act as a legitimate user. Upgrade to Jackrabbit 2.23.6, 2.22.5, or 2.20.18 as soon as possible to fix the problem.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | apache software foundation | apache jackrabbit | <= 2.23.5 |
| Debian:12 | debian | jackrabbit | All versions |
| Ubuntu:14.04:LTS | canonical | jackrabbit | All versions |
Original advisory text
DEBIAN-CVE-2026-92414
: Session Fixation / Session Reuse across Users vulnerability in Apache Jackrabbit. Jackrabbit WebDAV server attaches a cached authenticated session on any Lock-Token/TransactionId/SubscriptionId/If-header field token match with no credential check. This issue affects Apache Jackrabbit: from 2.23.0 through 2.23.5, from 2.22.0 through 2.22.4, from 2.20.0 through 2.20.17. Users are recommended to upgrade to versions 2.23.6, 2.22.5, or 2.20.18 which fix the issue.
References
- https://lists.apache.org/thread.html/gmbsmrs2lycl9nld7rd0h1r1fc4t75qr
- http://www.openwall.com/lists/oss-security/2026/10/07/27
- https://ubuntu.com/security/CVE-2026-92414 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-92414 Third Party Advisory
- https://www.openwall.com/lists/oss-security/2026/10/07/27 Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2026-92414 Vendor Advisory
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Severity
9.1
Critical
Type
CWE-384Session Fixation
Timeline
Published7 Oct 2026
Updated9 Oct 2026
First seen7 Oct 2026
Sources
CVE-2026-92414 · NVD
CVE-2026-92414 · MITRE
DEBIAN-CVE-2026-92414 · OSV
UBUNTU-CVE-2026-92414 · OSV
Track software like this
Free during beta