Executive brief
Apache Wicket, a popular Java web application framework, contains a vulnerability where it uses insufficiently random values for security-sensitive operations. This could allow an attacker to bypass certain protection mechanisms, potentially leading to unauthorized access or session hijacking. Organizations using affected versions should upgrade to version 10.10.0 to ensure their web applications remain secure.
Technical details
The vulnerability is classified under CWE-330 (Use of Insufficiently Random Values) and CWE-693 (Protection Mechanism Failure) within the Apache Wicket framework. The root cause is the generation of predictable or weak random values used in security contexts, which undermines the effectiveness of built-in protection mechanisms. While specific exploitation details are not provided in the advisory, such flaws typically allow for session prediction, CSRF token bypass, or other cryptographic attacks. The issue is resolved in Apache Wicket version 10.10.0.
Affected products
- Apache Wicket 9.0.0 through 9.23.0, 10.0.0 through 10.9.0
Timeline
- 2026-07-27: advisory: NVD published the CVE record based on Apache Software Foundation data.
- 2026-07-27: disclosed