CVE-2026-92414 PUBLISHED

Apache Jackrabbit: Pre-auth hijack of cached sessions via derivable WebDAV lock tokens

Assigner: apache
Reserved: 16.09.2026 Published: 07.10.2026 Updated: 07.10.2026

: Session Fixation / Session Reuse across Users vulnerability in Apache Jackrabbit.

Jackrabbit WebDAV server attaches a cached authenticated session on any Lock-Token/TransactionId/SubscriptionId/If-header field token match with

no credential check.

This issue affects Apache Jackrabbit: from 2.23.0 through 2.23.5, from 2.22.0 through 2.22.4, from 2.20.0 through 2.20.17.

Users are recommended to upgrade to versions 2.23.6, 2.22.5, or 2.20.18 which fix the issue.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor Apache Software Foundation
Product Apache Jackrabbit
Versions Default: unaffected
  • affected from 2.23.0 to 2.23.5 (incl.)
  • affected from 2.22.0 to 2.22.4 (incl.)
  • affected from 2.20.0 to 2.20.17 (incl.)

Credits

  • The Apache Software Foundation finder
  • Julian Reschke analyst
  • Claude Security tool

References

Problem Types

  • CWE-384: Session Fixation / Session Reuse across Users CWE