Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-92415— Apache Jackrabbit: DavEx client runs Class.forName + (String)-constructor on server-controlled error bodies

Quick assessment

Affected
Apache Software Foundation Apache Jackrabbit
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Apache Jackrabbit 的 WebDAV/DavEx 客户端中存在“使用外部可控输入选择类或代码”漏洞。 恶意 WebDAV/DavEx 服务器,或能够拦截连接的攻击者,可以诱使客户端从其类路径中实例化任意类,从而导致任意文件的创建或截断。 仅那些直接使用 jackrabbit-spi2dav 或通过 jackrabbit-jcr2dav 间接使用该组件以连接远程仓库的应用程序受到影响。Jackrabbit 服务器本身不受此漏洞影响。 类别:对网络数据进行不安全反射(高危)。 该问题影响 Apache

CVSS 6.9 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-92415

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache Jackrabbit: DavEx client runs Class.forName + (String)-constructor on server-controlled error bodies
Source: CVE Program / CVE List V5
Vulnerability Description
— Use of Externally-Controlled Input to Select Classes or Code vulnerability in Apache Jackrabbit's WebDAV/Davex client. A malicious WebDAV/DavEx server, or an attacker able to intercept the connection, can cause the client to instantiate arbitrary classes from its classpath, which can lead to arbitrary file creation or truncation. Only applications that use jackrabbit-spi2dav (directly or through jackrabbit-jcr2dav) to connect to a remote repository are affected. Jackrabbit servers are not affected. Category: unsafe reflection on wire data (HIGH). This issue affects Apache Jackrabbit: from 2.23.0 through 2.23.5, from 2.22.0 through 2.22.4, from 2.20.0 through 2.20.17. Users are recommended to upgrade to versions 2.23.6, 2.22.5, or 2.20.18 which fix the issue.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/S:N
Source: CVE Program / CVE List V5
Vulnerability Type
使用外部可控制的输入来选择类或代码(不安全的反射)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Apache Software Foundation Apache Jackrabbit 2.23.0 ~ 2.23.5 -

II. Public POCs for CVE-2026-92415

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-92415

请登录查看更多情报信息。

Other References for CVE-2026-92415 (1)

Same Patch Batch · Apache Software Foundation · 2026-10-07 · 8 CVEs total

CVE-2026-92414 9.3 CRITICAL Apache Jackrabbit: Pre-auth hijack of cached sessions via derivable WebDAV lock tokens
CVE-2026-97146 4.8 MEDIUM Apache YuniKorn: Admission control bypass via system label forgery
CVE-2026-78243 2.1 LOW Apache YuniKorn: LDAP Group provider panics on lowercase attribute name
CVE-2026-92393 2.0 LOW Apache YuniKorn: Admission control bypass via workload UPDATE operation
CVE-2026-93684 Apache Impala: Stored XSS in Impala query plans
CVE-2026-90466 Apache Impala: Path traversal executes JARs outside trusted paths
CVE-2026-97720 Apache Impala: Impala Executor Webserver Auth Bypass

IV. Related Vulnerabilities

V. Comments for CVE-2026-92415

No comments yet


Leave a comment