TL;DR
The Apache Software Foundation has patched two Apache Jackrabbit vulnerabilities in its WebDAV components. The worst, CVE-2026-92414, scores 9.3 on CVSS 4.0 and lets an attacker hijack a cached logged-in session. Users should upgrade to Jackrabbit 2.23.6, 2.22.5 or 2.20.18.
- Product: Apache Software Foundation Apache Jackrabbit
- Vulnerabilities: 2 flaws (CVE-2026-92414, CVE-2026-92415)
- Highest severity: 9.3 (Critical Β· CVSSv4)
- Worst impact: Pre-auth hijack of cached sessions via derivable WebDAV lock tokens
- Status: No confirmed exploitation yet
- Action: See vendor advisories
| CVE | CVSS (CVSSv4) | Type | Status |
|---|---|---|---|
| CVE-2026-92414 | 9.3 | Pre-auth hijack of cached sessions via derivable WebDAV lock tokens | Not exploited |
| CVE-2026-92415 | 6.9 | DavEx client runs Class.forName + (String)-constructor on server-controlled error bodies | Not exploited |
CISA KEV isn't the only exploit signal for Apache CVEs. Pro/Team adds a second confirmed-exploit feed.
Try free for 14 daysWhy It Matters
Jackrabbit is the reference implementation of the Java Content Repository standard. Many content management systems build on it. As a result, a flaw in its WebDAV server can expose stored content and let an attacker change it. The records list the exploitation status as unknown, and no public proof-of-concept has been confirmed.
How the Attacks Work
Session Hijack (CVE-2026-92414)
The Jackrabbit WebDAV server caches sessions for logged-in users. According to the advisory, it attaches one of those sessions on a matching lock, transaction or subscription token “with no credential check.” Apache’s record title adds that these tokens are “derivable,” so an unauthenticated attacker can take over another user’s session.
Unsafe Reflection (CVE-2026-92415)
The second bug, rated 6.9, sits in the WebDAV/DavEx client. A malicious server, or an attacker who can intercept the connection, can make the client load arbitrary classes. That “can lead to arbitrary file creation or truncation.” Only apps that use jackrabbit-spi2dav to reach a remote repository are affected.
Who Found the Bugs
Apache’s internal team discovered both issues. The records credit Julian Reschke as analyst and list Claude Security as a tool used in the work.
Affected Versions
Both Apache Jackrabbit vulnerabilities affect these releases:
- 2.23.0 through 2.23.5
- 2.22.0 through 2.22.4
- 2.20.0 through 2.20.17
Patch and Mitigation Steps
Upgrade to version 2.23.6, 2.22.5 or 2.20.18. The fixed builds are on the Apache Jackrabbit downloads page. Until then, the Apache Jackrabbit vulnerabilities remain open, so avoid exposing the WebDAV server to untrusted networks, and use TLS for client connections to remote repositories.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!