Apache Wicket XSS via Improper Neutralization of Input (Palette) 8.0-10.10
CVE-2026-76985 Published on August 31, 2026
Apache Wicket: XSS in Palette via getAdditionalAttributes
Improper neutralization of input during web page generation in Apache Wicket.
org.apache.wicket.extensions.markup.html.form.palette.component.AbstractOptions, which renders the two option lists of a Palette, escapes the id and the display value of each option according to the escape-model-strings setting, and wrote the attribute names and values returned by getAdditionalAttributes into the <option> tag as they came.
An application is affected where it overrides Palette.getAdditionalAttributesForChoices, Palette.getAdditionalAttributesForSelection or AbstractOptions.getAdditionalAttributes and returns a value holding data an attacker can influence. These methods return null by default, so an application that does not override them is not affected.
As a workaround, escape the values in the override.
This issue affects Apache Wicket: from 8.0.0 through 8.18.0, from 9.0.0 through 9.23.0, from 10.0.0 through 10.10.0. Older, unsupported releases from 1.4.0 onwards are also affected. Users are recommended to upgrade to version 8.19.0, 9.24.0 or 10.11.0, which fix the issue.
Vulnerability Analysis
CVE-2026-76985 can be exploited with network access. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Type
What is a XSS Vulnerability?
The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVE-2026-76985 has been classified to as a XSS vulnerability or weakness.
Products Associated with CVE-2026-76985
Want to know whenever a new CVE is published for Apache Wicket? stack.watch will email you.
Affected Versions
Apache Software Foundation Apache Wicket:- Version 8.0.0, <= 8.18.0 is affected.
- Version 9.0.0, <= 9.23.0 is affected.
- Version 10.0.0, <= 10.10.0 is affected.