Apache Jackrabbit WebDAV Session Fixation via Lock-Token (Pre-2.23.6)
CVE-2026-92414 Published on October 7, 2026
Apache Jackrabbit: Pre-auth hijack of cached sessions via derivable WebDAV lock tokens
: Session Fixation / Session Reuse across Users vulnerability in Apache Jackrabbit.
Jackrabbit WebDAV server attaches a cached authenticated session on any Lock-Token/TransactionId/SubscriptionId/If-header field token match with
no credential check.
This issue affects Apache Jackrabbit: from 2.23.0 through 2.23.5, from 2.22.0 through 2.22.4, from 2.20.0 through 2.20.17.
Users are recommended to upgrade to versions 2.23.6, 2.22.5, or 2.20.18 which fix the issue.
Vulnerability Analysis
CVE-2026-92414 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Type
Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
Products Associated with CVE-2026-92414
Want to know whenever a new CVE is published for Apache Jackrabbit? stack.watch will email you.
Affected Versions
Apache Software Foundation Apache Jackrabbit:- Version 2.23.0, <= 2.23.5 is affected.
- Version 2.22.0, <= 2.22.4 is affected.
- Version 2.20.0, <= 2.20.17 is affected.