Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-92414— Apache Jackrabbit: Pre-auth hijack of cached sessions via derivable WebDAV lock tokens

Quick assessment

Affected
Apache Software Foundation Apache Jackrabbit
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Apache Jackrabbit 中存在的跨用户会话固定/会话重用漏洞。 Jackrabbit WebDAV 服务器在未进行任何凭据验证的情况下,会将已认证的缓存会话与任何 Lock-Token、TransactionId、SubscriptionId 或 If 请求头字段中的令牌进行匹配并绑定。 该漏洞影响以下版本的 Apache Jackrabbit: 2.23.0 至 2.23.5 2.22.0 至 2.22.4 2.20.0 至 2.20.17 建议用户升级至修复此问题的版本:2.23.6、2.22.5

CVSS 9.3 · Critical

Possible ATT&CK Techniques 1 AI

T1528 · Steal Application Access Token
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-92414

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache Jackrabbit: Pre-auth hijack of cached sessions via derivable WebDAV lock tokens
Source: CVE Program / CVE List V5
Vulnerability Description
: Session Fixation / Session Reuse across Users vulnerability in Apache Jackrabbit. Jackrabbit WebDAV server attaches a cached authenticated session on any Lock-Token/TransactionId/SubscriptionId/If-header field token match with no credential check. This issue affects Apache Jackrabbit: from 2.23.0 through 2.23.5, from 2.22.0 through 2.22.4, from 2.20.0 through 2.20.17. Users are recommended to upgrade to versions 2.23.6, 2.22.5, or 2.20.18 which fix the issue.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
会话固定
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Apache Software Foundation Apache Jackrabbit 2.23.0 ~ 2.23.5 -

II. Public POCs for CVE-2026-92414

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-92414

请登录查看更多情报信息。

Other References for CVE-2026-92414 (1)

Same Patch Batch · Apache Software Foundation · 2026-10-07 · 8 CVEs total

CVE-2026-92415 6.9 MEDIUM Apache Jackrabbit: DavEx client runs Class.forName + (String)-constructor on server-contro
CVE-2026-97146 4.8 MEDIUM Apache YuniKorn: Admission control bypass via system label forgery
CVE-2026-78243 2.1 LOW Apache YuniKorn: LDAP Group provider panics on lowercase attribute name
CVE-2026-92393 2.0 LOW Apache YuniKorn: Admission control bypass via workload UPDATE operation
CVE-2026-93684 Apache Impala: Stored XSS in Impala query plans
CVE-2026-90466 Apache Impala: Path traversal executes JARs outside trusted paths
CVE-2026-97720 Apache Impala: Impala Executor Webserver Auth Bypass

IV. Related Vulnerabilities

V. Comments for CVE-2026-92414

No comments yet


Leave a comment