Severity: 
    CVSS 4.0: 9.3 (critical) 
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Affected versions:

- Apache Jackrabbit 2.23.0 through 2.23.5
- Apache Jackrabbit 2.22.0 through 2.22.4
- Apache Jackrabbit 2.20.0 through 2.20.17

Description:

: Session Fixation / Session Reuse across Users vulnerability in Apache 
Jackrabbit.



Jackrabbit WebDAV server attaches a cached authenticated session on any 
Lock-Token/TransactionId/SubscriptionId/If-header field token match with

no credential check.



This issue affects Apache Jackrabbit: from 2.23.0 through 2.23.5, from 2.22.0 
through 2.22.4, from 2.20.0 through 2.20.17.












Users are recommended to upgrade to versions 2.23.6, 2.22.5, or 2.20.18 which 
fix the issue.

Credit:

The Apache Software Foundation (finder)
Julian Reschke (analyst)
Claude Security (tool)

References:

https://jackrabbit.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-92414

Reply via email to