PatchSiren cyber security CVE debrief
CVE-2026-28813 Apache Software Foundation CVE debrief
Apache JSPWiki up to 2.12.3 is vulnerable to JSON Hijacking, leading to CSRF vulnerabilities. The vulnerability has a CVSS score of 8.8 and is classified as HIGH. Users are recommended to upgrade to version 2.12.4, which fixes this issue. However, the specific details of the vulnerability and its potential impact are not well understood at this time. Affected deployments should be identified and owners assigned for follow-up. Official advisories and CVE records should be reviewed to validate affected scope, severity, and vendor guidance. Until mitigation is confirmed, compensating controls for exposed systems should be reviewed. Relevant monitoring, detection, and logs for exposed assets require extra review.
- Vendor
- Apache Software Foundation
- Product
- JSPWiki
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-30
- Original CVE updated
- 2026-07-31
- Advisory published
- 2026-07-30
- Advisory updated
- 2026-07-31
Who should care
Users of Apache JSPWiki up to version 2.12.3 should upgrade to version 2.12.4 to fix the JSON Hijacking vulnerability. This is particularly important for operators and security teams who manage and maintain JSPWiki deployments, as the vulnerability could lead to unauthorized actions being performed on behalf of the user. Additionally, platform administrators and vulnerability management teams should be aware of the vulnerability and take steps to mitigate it.
Technical summary
Apache JSPWiki up to 2.12.3 is vulnerable to JSON Hijacking, which leads to CSRF vulnerabilities. The vulnerability has a CVSS score of 8.8 and is classified as HIGH. The vulnerability is caused by the lack of proper validation of user input, allowing an attacker to inject malicious JSON code. This could lead to unauthorized actions being performed on behalf of the user. Users are recommended to upgrade to version 2.12.4, which fixes this issue. However, the specific details of the vulnerability and its potential impact are not well understood at this time.
Defensive priority
Upgrade to version 2.12.4 to fix JSON Hijacking vulnerability.
Recommended defensive actions
- Upgrade to version 2.12.4
- Review and apply patches
- Monitor for suspicious activity
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The CVE record was published on 2026-07-30T16:17:11.070Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. There is limited information available about the vulnerability, and defenders should verify the affected scope and severity with the vendor. The JSON Hijacking vulnerability in Apache JSPWiki up to 2.12.3 could lead to CSRF vulnerabilities, and users are recommended to upgrade to version 2.12.4. However, the specific details of the vulnerability and its potential impact are not well understood at this time.
Official resources
-
CVE-2026-28813 CVE record
CVE.org
-
CVE-2026-28813 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
-
Source reference
af854a3a-2127-422b-91ae-364da2661108
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T16:17:11.070Z and has not been modified since then.