CVE-2026-92414

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

: Session Fixation / Session Reuse across Users vulnerability in Apache Jackrabbit. Jackrabbit WebDAV server attaches a cached authenticated session on any Lock-Token/TransactionId/SubscriptionId/If-header field token match with no credential check. This issue affects Apache Jackrabbit: from 2.23.0 through 2.23.5, from 2.22.0 through 2.22.4, from 2.20.0 through 2.20.17. Users are recommended to upgrade to versions 2.23.6, 2.22.5, or 2.20.18 which fix the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-384

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 2 mentions (2026-10-07); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-10-07: 2Mentions · 2026-10-08: 110-0710-08
Referenced assets2 URLs
Full discourse3 posts
  • Atlas Threat Monitoring@ThreatAtlas

    Unpatched vulnerabilities don't stay hidden on our atlas. #CVE CRITICAL VULNERABILITY DETECTED CVE ID → CVE-2026-92414 Vendor → Unknown Severity → Critical — CVSS 9.3 Product → Unknown Date → 2026-10-07 A critical vulnerability (Session Fixation) has been disclosed affecting Unknown. Patch immediately. Powered by @Brandefense #ThreatIntel #CyberSecurity #CVE #Unknown

    0000040
    451 followersView on X
  • VulniPulse@vulnipulse

    CVE advisory (CRITICAL): CVE-2026-92414 - apache: Apache Jackrabbit: Pre-auth hijack of cached sessions via derivable WebDAV lock tokens. https://vulnipulse.com/advisories/apache-cve-2026-92414 #CVE #CyberSecurity #Apache #ApacheJackrabbit

    0000028
    7 followersView on X
  • Daily CyberSecurity@Daily_CyberSec

    Two Apache Jackrabbit vulnerabilities, including critical session hijack flaw CVE-2026-92414 (CVSS 9.3), are fixed. Upgrade to 2.23.6 now. #Apache #Jackrabbit #WebDAV #CVE202692414 #CVE202692415 #SessionHijack #Java #Vulnerability https://securityonline.info/apache-jackrabbit-vulnerabilities/

    00000358
    13.0K followersView on X

Explore more