Apache Jackrabbit WebDAV Session Fixation via Lock-Token (Pre-2.23.6)
CVE-2026-92414 Published on October 7, 2026

Apache Jackrabbit: Pre-auth hijack of cached sessions via derivable WebDAV lock tokens
: Session Fixation / Session Reuse across Users vulnerability in Apache Jackrabbit. Jackrabbit WebDAV server attaches a cached authenticated session on any Lock-Token/TransactionId/SubscriptionId/If-header field token match with no credential check. This issue affects Apache Jackrabbit: from 2.23.0 through 2.23.5, from 2.22.0 through 2.22.4, from 2.20.0 through 2.20.17. Users are recommended to upgrade to versions 2.23.6, 2.22.5, or 2.20.18 which fix the issue.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-92414 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE

Weakness Type

Session Fixation

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.


Products Associated with CVE-2026-92414

Want to know whenever a new CVE is published for Apache Jackrabbit? stack.watch will email you.

 

Affected Versions

Apache Software Foundation Apache Jackrabbit: