Executive brief
Apache JSPWiki, a popular open-source wiki engine, contains a security flaw where it fails to properly verify user identity before processing certain commands. This allows an unauthorized person to trick the system into displaying internal information and sensitive data stored within the wiki's variables. Organizations using this software should update to the latest version to prevent potential data exposure.
Technical details
A vulnerability in Apache JSPWiki (up to version 2.12.3) stems from a lack of authentication when rendering arbitrary wiki markup. An unauthenticated attacker can leverage this to execute specific wiki commands or markup that retrieves and displays the values of JSPWiki internal variables. This could lead to the disclosure of sensitive configuration or session-related data. The issue is resolved in versions 2.12.4 and 3.0.0. While the NVD entry lists the severity as 'info', the original Apache advisory classifies it as 'Critical'.
Affected products
- Apache Software Foundation JSPWiki up to 2.12.3
Timeline
- 2026-07-30: disclosed
- 2026-07-30: advisory