Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-92414: Apache Jackrabbit may let attackers hijack user sessions

CVE-2026-92414 · published 2 days ago
Summary

The Jackrabbit content repository used in your web applications can mistakenly accept an existing authenticated session when certain request headers match, allowing one user to take over another's session. This can expose sensitive data or let an attacker act as a legitimate user. Upgrade to Jackrabbit 2.23.6, 2.22.5, or 2.20.18 as soon as possible to fix the problem.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
Ecosystem VendorProductAffected versions
– apache software foundation apache jackrabbit <= 2.23.5
Debian:12 debian jackrabbit All versions
Ubuntu:14.04:LTS canonical jackrabbit All versions
Original advisory text
DEBIAN-CVE-2026-92414
: Session Fixation / Session Reuse across Users vulnerability in Apache Jackrabbit. Jackrabbit WebDAV server attaches a cached authenticated session on any Lock-Token/TransactionId/SubscriptionId/If-header field token match with no credential check. This issue affects Apache Jackrabbit: from 2.23.0 through 2.23.5, from 2.22.0 through 2.22.4, from 2.20.0 through 2.20.17. Users are recommended to upgrade to versions 2.23.6, 2.22.5, or 2.20.18 which fix the issue.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.1 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-384Session Fixation
Timeline
Published7 Oct 2026
Updated9 Oct 2026
First seen7 Oct 2026
Track software like this
Free during beta