Junglewise Threat Intelligence

CVE-2026-28811: Apache JSPWiki information disclosure in debug messages

CVE-2026-28811 · Severity: info · CVSS 3.7 · Published 2026-07-30

Executive brief

Apache JSPWiki, a popular open-source wiki engine, contains a vulnerability where it may reveal sensitive technical information through debug or error messages. This could allow an unauthorized person to see internal system details that could be used to plan further attacks. Organizations using this software should update to the latest version to ensure these details are properly hidden.

Technical details

A CWE-1295 vulnerability exists in Apache JSPWiki versions up to 2.12.3 due to improper error handling. The application's debug messages and error responses reveal sensitive internal information that should not be exposed to end-users. This information disclosure occurs over the network without requiring authentication. An attacker can leverage these details to gain insights into the application's internal state, configuration, or environment, potentially aiding in the development of more sophisticated exploits. The issue is resolved in version 2.12.4.

Affected products

  • Apache Software Foundation JSPWiki up to 2.12.3

Timeline

  • 2026-07-30: disclosed
  • 2026-07-30: advisory
  • 2026-07-30: patched: Fixed in version 2.12.4

References

Related threats