Junglewise Threat Intelligence

CVE-2026-66391: Apache Wicket protection mechanism failure via weak randomness

CVE-2026-66391 · Severity: info · Published 2026-07-27

Technologies: Apache Software Foundation Wicket. Vendors: Apache, Apache Software Foundation.

Executive brief

Apache Wicket, a popular Java web application framework, contains a vulnerability where it uses insufficiently random values for security-sensitive operations. This could allow an attacker to bypass certain protection mechanisms, potentially leading to unauthorized access or session hijacking. Organizations using affected versions should upgrade to version 10.10.0 to ensure their web applications remain secure.

Technical details

The vulnerability is classified under CWE-330 (Use of Insufficiently Random Values) and CWE-693 (Protection Mechanism Failure) within the Apache Wicket framework. The root cause is the generation of predictable or weak random values used in security contexts, which undermines the effectiveness of built-in protection mechanisms. While specific exploitation details are not provided in the advisory, such flaws typically allow for session prediction, CSRF token bypass, or other cryptographic attacks. The issue is resolved in Apache Wicket version 10.10.0.

Affected products

  • Apache Wicket 9.0.0 through 9.23.0, 10.0.0 through 10.9.0

Timeline

  • 2026-07-27: advisory: NVD published the CVE record based on Apache Software Foundation data.
  • 2026-07-27: disclosed

References

Related threats