CVE-2026-43975Disclosure(apache / wicket)

LOWCVSS 6.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch apache wicket systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

FolderUploadsFileManager in Apache Wicket does not validate or sanitize the uploadFieldId parameter or the clientFileName before constructing file paths, allowing an unauthenticated attacker to write arbitrary files outside the intended upload directory or read files from arbitrary locations on the server. This issue affects Apache Wicket: from 8.0.0 through 8.17.0, from 9.0.0 through 9.22.0, from 10.0.0 through 10.8.0. Users are recommended to upgrade to version 10.9.0, which fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wicket

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-05-06); latest day: 2
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
wicket

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-05-06: 3Mentions · 2026-05-07: 2Patch / Workaround · 2026-05-07: 2Technical Details · 2026-05-06: 2Technical Details · 2026-05-07: 205-0605-07
Signal classification3 categories
Disclosure
240.0%
Patch
240.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-063
Disclosure2General1
2026-05-072
Patch2
Full discourse5 posts
  • Gray Hats@the_yellow_fall
    Patch

    Apache Wicket 10.9.0 fixes 3 Critical flaws: Path Traversal (CVE-2026-43975), Session Fixation, and Resource Guard bypass. Secure your Java apps and patch now! #ApacheWicket #JavaSecurity #InfoSec #CyberSecurity #WebDev #PathTraversal #SessionFixation https://securityonline.info/apache-wicket-critical-vulnerabilities-path-traversal-session-fixation-10-9-0/ https://t.co/4F4gRQXyCa

    Post summary

    The post announces that Apache Wicket 10.9.0 fixes critical path traversal, session fixation, and resource guard bypass flaws, urging users to apply the patch immediately.

    10041350
    12.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-43975 FolderUploadsFileManager in Apache Wicket does not validate or sanitize the uploadFieldId parameter or the clientFileName before constructing file paths, allowing an… https://www.cve.org/CVERecord?id=CVE-2026-43975

    Post summary

    The text announces CVE-2026-43975, describing a file path sanitization flaw in Apache Wicket's FolderUploadsFileManager.

    00010205
    57.4K followersView on X
  • VulnTracker@vuln_tracker
    Patch

    @the_yellow_fall Path traversal + session fixation + resource guard bypass in a single release. If you're running Apache Wicket in prod and haven't patched to 10.9.0 yet, you've got a busy afternoon ahead. CVE-2026-43975 and the full cluster are live at http://vulntracker.io

    Post summary

    The post highlights CVE‑2026‑43975’s path traversal, session fixation, and resource guard bypass vulnerabilities in Apache Wicket and urges users to update to version 10.9.0.

    0000055
    619 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-43975 FolderUploadsFileManager in Apache Wicket does not validate or sanitize the uploadFieldId parameter or the clientFileName before constructing file paths, allowing an… https://www.cve.org/CVERecord?id=CVE-2026-43975 ----- Traducción: CVE-2026-43975 Fol… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-43975 in Apache Wicket, providing a brief technical overview and a link to the official CVE record, but offers no proof of exploitation, tools, or mitigations.

    0000040
    75 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-43975 CVE-2026-43975 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-43975

    Post summary

    The post merely repeats the CVE ID and includes a link, with no further information on exploitation, patching, or technical details.

    0000047
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachewicket---

Explore more