: Session Fixation / Session Reuse across Users vulnerability in Apache Jackrabbit.
Jackrabbit WebDAV server attaches a cached authenticated session on any Lock-Token/TransactionId/SubscriptionId/If-header field token match with
no credential check.
This issue affects Apache Jackrabbit: from 2.23.0 through 2.23.5, from 2.22.0 through 2.22.4, from 2.20.0 through 2.20.17.
Users are recommended to upgrade to versions 2.23.6, 2.22.5, or 2.20.18 which fix the issue.
Jackrabbit WebDAV server attaches a cached authenticated session on any Lock-Token/TransactionId/SubscriptionId/If-header field token match with
no credential check.
This issue affects Apache Jackrabbit: from 2.23.0 through 2.23.5, from 2.22.0 through 2.22.4, from 2.20.0 through 2.20.17.
Users are recommended to upgrade to versions 2.23.6, 2.22.5, or 2.20.18 which fix the issue.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 07 Oct 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 07 Oct 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | : Session Fixation / Session Reuse across Users vulnerability in Apache Jackrabbit. Jackrabbit WebDAV server attaches a cached authenticated session on any Lock-Token/TransactionId/SubscriptionId/If-header field token match with no credential check. This issue affects Apache Jackrabbit: from 2.23.0 through 2.23.5, from 2.22.0 through 2.22.4, from 2.20.0 through 2.20.17. Users are recommended to upgrade to versions 2.23.6, 2.22.5, or 2.20.18 which fix the issue. | |
| Title | Apache Jackrabbit: Pre-auth hijack of cached sessions via derivable WebDAV lock tokens | |
| Weaknesses | CWE-384 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-10-07T16:09:31.492Z
Reserved: 2026-09-16T09:33:25.002Z
Link: CVE-2026-92414
No data.
Status : Received
Published: 2026-10-07T16:19:12.900
Modified: 2026-10-07T17:17:02.453
Link: CVE-2026-92414
No data.
OpenCVE Enrichment
No data.
Weaknesses