Junglewise Threat Intelligence

CVE-2026-66390: Apache Wicket cross-site scripting vulnerability

CVE-2026-66390 · Severity: info · Published 2026-07-27

Vendors: Apache.

Executive brief

Apache Wicket, a popular framework for building Java web applications, contains a security vulnerability that could allow attackers to inject malicious scripts into web pages viewed by other users. If exploited, this could lead to unauthorized actions being performed in a user's browser, such as stealing session cookies or redirecting users to malicious websites. Organizations using affected versions should upgrade to version 10.10.0 to protect their users and data.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in Apache Wicket versions 9.x and 10.x due to improper neutralization of user-supplied input during the generation of web pages (CWE-79). An unauthenticated remote attacker could exploit this by sending specially crafted input that is subsequently rendered by the application without sufficient validation or escaping. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session. The issue is resolved in Apache Wicket version 10.10.0.

Affected products

  • Apache Wicket 9.0.0 through 9.23.0, 10.0.0 through 10.9.0

Timeline

  • 2026-07-27: advisory: Initial advisory published by Apache Software Foundation
  • 2026-07-27: patched: Fix released in version 10.10.0

References