CVE-2026-92414: Apache Software Foundation Apache Jackrabbit

Critical severity, CVSS 9.3. EPSS: 0.6% chance of exploitation in the next 30 days.

: Session Fixation / Session Reuse across Users vulnerability in Apache Jackrabbit. Jackrabbit WebDAV server attaches a cached authenticated session on any Lock-Token/TransactionId/SubscriptionId/If-header field token match with no credential check. This issue affects Apache Jackrabbit: from 2.23.0 through 2.23.5, from 2.22.0 through 2.22.4, from 2.20.0 through 2.20.17. Users are recommended to upgrade to versions 2.23.6, 2.22.5, or 2.20.18 which fix the issue.

Affected products

  • Apache Software Foundation Apache Jackrabbit: from 2.23.0, up to and including 2.23.5; from 2.22.0, up to and including 2.22.4; from 2.20.0, up to and including 2.20.17

Published 2026-10-07. Last modified 2026-10-08.