CVE-2026-40010General(apache / wicket)

MEDIUMCVSS 9.1 · CRITICAL

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch apache wicket systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Missing invocation of Servlet http web request method changeSessionId after session binding can be exploited for a session fixation attack in Apache Wicket. This issue affects Apache Wicket: from 8.0.0 through 8.17.0, 9.0.0, from 10.0.0 through 10.8.0. Users are recommended to upgrade to version 10.9.0, which fixes the issue.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-384

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wicket

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 12 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 8 signals
  • General: 6 classified signals
  • Disclosure: 4 classified signals
  • Peaked 3d ago at 5 mentions (2026-05-06); latest day: 1
  • 12 total mentions across 4 days

Affected systems

Vendors
Products
wicket

Deep dive

Activity timeline12 mentions / 4d
01345Mentions · 2026-05-06: 5Mentions · 2026-05-12: 5Mentions · 2026-05-14: 1Mentions · 2026-05-30: 1Active Exploitation · 2026-05-06: 1Patch / Workaround · 2026-05-06: 1Technical Details · 2026-05-06: 4Technical Details · 2026-05-12: 405-0605-1205-1405-30
Signal classification4 categories
General
650.0%
Disclosure
433.3%
Active Exploitation
18.3%
Patch
18.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-065
Active Exploitation1Disclosure1General2Patch1
2026-05-125
Disclosure3General2
2026-05-141
General1
2026-05-301
General1
Full discourse12 posts
  • z3n@zench4n
    General

    Securing agents requires more than just sanitizing prompts. You must enforce strict principle of least privilege on tool access and implement robust session integrity. Look at CVE-2026-40010; session binding flaws can be weaponized when agents handle stateful web requests.

    Post summary

    The post references CVE‑2026‑40010, noting that session binding flaws could be weaponized in agent applications, but provides no in‑depth detail or actionable guidance.

    1000068
    1.4K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    References CVE: CVE-2026-40010 CVSS: 9.1 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Severity: CRITICAL Status: Critical advisory

    Post summary

    The text references CVE-2026-40010 as a critical vulnerability with a CVSS score of 9.1, but contains no further technical details, exploit code, or mitigation information.

    1000052
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CRITICAL: CVE-2026-40010 (CVSS 9.1) — apache wicket. CVE: CVE-2026-40010 CVSS: 9.1 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Severity: CRITICAL Status: Critical advisory

    Post summary

    A critical advisory for CVE-2026-40010 in Apache Wicket issued with a CVSS score of 9.1; no PoC, exploit, or patch details are provided.

    1000054
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    This issue affects Apache Wicket: from 8.0.0 through 8.17.0, 9.0.0, from 10.0.0 through 10.8.0. CVE: CVE-2026-40010 CVSS: 9.1 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Severity: CRITICAL Status: Critical advisory

    Post summary

    The advisory announces a critical remote code execution vulnerability (CVE‑2026‑40010) in Apache Wicket version ranges 8.0.0–8.17.0, 9.0.0, and 10.0.0–10.8.0, with a CVSS v3.1 score of 9.1, but offers no PoC, exploit, or mitigation details.

    1000051
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-40010 CVSS: 9.1 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Severity: CRITICAL Status: Critical advisory Missing invocation of Servlet http web request method changeSessionId after session binding can be exploited for a session fixation attack in…

    Post summary

    The text announces a critical advisory for CVE‑2026‑40010, detailing a session fixation flaw caused by a missing changeSessionId call and noting a high CVSS score, but it does not provide PoC, exploit, patch, or indication of active exploitation.

    1000055
    210 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40010 Missing invocation of Servlet http web request method changeSessionId after session binding can be exploited for a session fixation attack in Apache Wicket. This iss… https://www.cve.org/CVERecord?id=CVE-2026-40010

    Post summary

    CVE-2026-40010 is a session fixation vulnerability in Apache Wicket caused by a missing call to changeSessionId after session binding.

    00010227
    57.4K followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    General

    【脆弱性情報】 CVE-2026-40010 Apache Wicketの脆弱性について https://www.cybernote.click/2026/05/20/%e3%80%90%e8%84%86%e5%bc%b1%e6%80%a7%e6%83%85%e5%a0%b1%e3%80%91-cve-2026-40010-apache-wicket%e3%81%ae%e8%84%86%e5%bc%b1%e6%80%a7%e3%81%ab%e3%81%a4%e3%81%84%e3%81%a6/ #IT #Security #cybersecurity

    Post summary

    The tweet references CVE-2026-40010 pertaining to Apache Wicket but offers no technical details, PoC, exploit, or patch information.

    0000088
    209 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-40010-apache-wicket #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The content merely links to a research page on CVE‑2026‑40010 with hashtags, providing no further detail or evidence of exploitation, patches, or technical specifics.

    0000030
    210 followersView on X
  • ByteGuard@byte_guard_blog
    Patch

    Session fixation attack via missing session ID change after binding. CVE-2026-40010, CVSS 9.1. Apache Wicket 8.0.0 to 8.17.0, 9.0.0, and 10.0.0 to 10.8.0. Upgrade to 10.9.0. #InfoSec #ApacheWicket

    Post summary

    Apache Wicket session fixation CVE‑2026‑40010 (CVSS 9.1) affects several versions; the mitigation recommended is upgrading to 10.9.0.

    0000077
    10 followersView on X
  • Technology Interpreters, Inc.@TechTranslators
    Active Exploitation

    Today (Wed, May 6): 1 KEV add, 10 critical CVEs. PAN-OS Captive Portal RCE went out earlier. Long tail: - Apache Wicket session fixation (CVE-2026-40010) - Nginx-UI unauth RCE (CVE-2026-42238, CVSS 9.8) - phpMyFAQ unauth SQL injection (GHSA-289f-fq7w-6q2w)

    Post summary

    The note announces a KEV update with ten critical CVEs that are actively exploited, listing their types and a CVSS score but providing no PoC or patch information.

    0000066
    34 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-40010 Missing invocation of Servlet http web request method changeSessionId after session binding can be exploited for a session fixation attack in Apache Wicket. This iss… https://www.cve.org/CVERecord?id=CVE-2026-40010 ----- Traducción: CVE-2026-40010 Fal… http://infoflow.cloud`

    Post summary

    The post mentions CVE-2026-40010, describing a session‑fixation flaw in Apache Wicket and linking to the CVE record, but provides no PoC, exploit, or mitigation details.

    0000069
    75 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-40010 CVE-2026-40010 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40010

    Post summary

    The text merely references CVE-2026-40010 with a link to a vulnerability database, offering no substantive information about the vulnerability or its exploitation.

    0000086
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachewicket---

Explore more