Junglewise Threat Intelligence

CVE-2026-43646: Apache Wicket information disclosure in PackageResourceGuard

CVE-2026-43646 · Severity: high · CVSS 7.5 · Published 2026-05-06

Technologies: Apache Software Foundation Wicket. Vendors: Apache, Apache Software Foundation.

Executive brief

Apache Wicket, a popular framework for building Java web applications, contains a security flaw that could allow unauthorized access to sensitive files. By using specially crafted web addresses, an attacker can bypass security filters intended to protect internal application resources. This could lead to the exposure of private configuration data or proprietary application code, potentially compromising the entire system.

Technical details

An information disclosure vulnerability exists in Apache Wicket's PackageResourceGuard component (CWE-200). The flaw allows a remote, unauthenticated attacker to bypass the guard's restrictions using crafted URLs to access resources that should be protected. This bypass enables the retrieval of sensitive files from the application's classpath or package resources. The issue affects multiple major versions (8.x, 9.x, and 10.x) and is resolved in version 10.9.0. Exploitation does not require user interaction or special privileges.

Affected products

  • Apache Wicket 8.0.0 through 8.17.0, 9.0.0 through 9.22.0, 10.0.0 through 10.8.0

Timeline

  • 2026-05-05: disclosed: Initial disclosure on oss-security mailing list
  • 2026-05-06: advisory: NVD and GitHub Advisory published
  • 2026-05-06: patched: Version 10.9.0 released to address the vulnerability

References

Related threats