Subject: Apache Jackrabbit Security Releases: CVE-2026-92414 and
CVE-2026-92415
The Apache Jackrabbit team would like to announce two security
vulnerabilities affecting Apache Jackrabbit.
CVE-2026-92414 — Critical
Session Fixation / Session Reuse across Users
Jackrabbit's WebDAV server can attach a cached authenticated session
based solely on a matching Lock-Token, TransactionId, SubscriptionId, or
If header token, without verifying credentials. This can allow a
pre-authenticated attacker to hijack or reuse cached sessions across users.
CVSS 4.0: 9.3 (Critical)
Affected versions:
* 2.23.0 through 2.23.5-beta
* 2.22.0 through 2.22.4
* 2.20.0 through 2.20.17
CVE-2026-92415 — Medium
Unsafe Reflection on WebDAV/DavEx Wire Data
A malicious WebDAV/DavEx server, or an attacker able to intercept the
connection, can cause the Jackrabbit DavEx client to instantiate
arbitrary classes from its classpath. This may result in arbitrary file
creation or truncation.
This vulnerability affects applications using jackrabbit-spi2dav,
directly or through jackrabbit-jcr2dav, to connect to a remote
repository. Jackrabbit servers themselves are not affected.
CVSS 4.0: 6.9 (Medium)
The same Jackrabbit versions are affected:
* 2.23.0 through 2.23.5-beta
* 2.22.0 through 2.22.4
* 2.20.0 through 2.20.17
Users are strongly recommended to upgrade to one of the following fixed
versions:
* Apache Jackrabbit 2.23.6-beta
* Apache Jackrabbit 2.22.5
* Apache Jackrabbit 2.20.18
Due to the critical severity of CVE-2026-92414, users are encouraged to
prioritize upgrading.