Junglewise Threat Intelligence

CVE-2026-5795: Eclipse Jetty privilege escalation in JASPIAuthenticator via ThreadLocal reuse

CVE-2026-5795 · Severity: high · CVSS 7.4 · Published 2026-04-08

Technologies: Eclipse Foundation Jetty, Red Hat Streams for Apache Kafka, Red Hat build of Apache Camel for Spring Boot. Vendors: Eclipse Foundation, Red Hat.

Executive brief

Eclipse Jetty, a widely used web server and servlet engine, contains a security flaw in its authentication component. Under specific conditions, the server fails to clear security credentials from a processing thread after a request is finished. This allows a subsequent user's request, if handled by the same thread, to inherit the previous user's identity and permissions, potentially leading to unauthorized access to sensitive data or administrative functions.

Technical details

A vulnerability exists in the JASPIAuthenticator class within Eclipse Jetty where authentication state is stored in ThreadLocal variables. When certain conditions trigger an early return from the authentication logic, these ThreadLocal variables are not explicitly cleared. Because Jetty utilizes thread pooling, a subsequent HTTP request processed by the same thread will inherit the stale security context. An unauthenticated attacker can potentially gain the privileges of a previously authenticated user. The vulnerability affects multiple major versions including 9.4.x, 10.0.x, 11.0.x, and 12.x. Fixes are typically addressed in versions immediately following the affected ranges (e.g., 12.1.8+, 12.0.34+).

Affected products

  • Eclipse Foundation Jetty 9.4.0 to 9.4.60, 10.0.0 to 10.0.28, 11.0.0 to 11.0.28, 12.0.0 to 12.0.33, 12.1.0 to 12.1.7
  • Red Hat Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14
  • Red Hat HawtIO 4.4.0
  • Red Hat Red Hat Offline Knowledge Portal 1.2.6
  • Red Hat streams for Apache Kafka 3

Timeline

  • 2026-04-08: advisory: Initial disclosure date
  • 2026-05-14: patched: Red Hat released security updates for Apache Camel for Spring Boot

References

Related threats