Apache JSPWiki 2.12.3 Debug Msg Exposed - Upgrade to 2.12.4
CVE-2026-28811 Published on July 30, 2026

Apache JSPWiki: Error Handling - Reveals Error Details
Debug Messages Revealing Unnecessary Information in Apache JSPWiki up to 2.12.3. Users are recommended to upgrade to version 2.12.4, which fixes this issue.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-28811 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity and availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
NONE
Availability Impact:
NONE

Weakness Type

Debug Messages Revealing Unnecessary Information

The product fails to adequately prevent the revealing of unnecessary and potentially sensitive system information within debugging messages.


Products Associated with CVE-2026-28811

Want to know whenever a new CVE is published for Apache JSPWiki? stack.watch will email you.

 

Affected Versions

Apache Software Foundation Apache JSPWiki: