PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-92415 Apache Software Foundation CVE debrief

Apache Jackrabbit's WebDAV/Davex client is vulnerable to an Externally-Controlled Input to Select Classes or Code issue. A malicious WebDAV/DavEx server or an attacker intercepting the connection can cause the client to instantiate arbitrary classes from its classpath, potentially leading to arbitrary file creation or truncation. This issue affects applications using jackrabbit-spi2dav or jackrabbit-jcr2dav to connect to a remote repository. Only applications that use jackrabbit-spi2dav (directly or through jackrabbit-jcr2dav) to connect to a remote repository are affected. Jackrabbit servers are not affected.

Vendor
Apache Software Foundation
Product
Apache Jackrabbit
CVSS
MEDIUM 6.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders of systems using Apache Jackrabbit's WebDAV/Davex client, specifically those connecting to remote repositories using jackrabbit-spi2dav or jackrabbit-jcr2dav, should assess exposure and prioritize remediation.

Why it matters

Defenders should care due to the potential for arbitrary file creation or truncation, risk of unauthorized data modification, need for inventory checks and version verification, and priority on upgrading to fixed versions.

  • Potential for arbitrary file creation or truncation
  • Risk of unauthorized data modification
  • Need for inventory checks and version verification
  • Priority on upgrading to fixed versions

Technical summary

The vulnerability in Apache Jackrabbit's WebDAV/Davex client allows a malicious server or intercepted connection to cause the client to instantiate arbitrary classes from its classpath. This can lead to arbitrary file creation or truncation. Affected versions include 2.23.0 through 2.23.5, 2.22.0 through 2.22.4, and 2.20.0 through 2.20.17. The issue arises from the client's handling of server-controlled error bodies, which can lead to unsafe reflection on wire data. Defenders should prioritize upgrading to fixed versions and perform inventory checks.

Defensive priority

Defenders should prioritize upgrading to versions 2.23.6, 2.22.5, or 2.20.18. Inventory checks are necessary to identify affected versions 2.23.0 through 2.23.5, 2.22.0 through 2.22.4, and 2.20.0 through 2.20.17.

Recommended defensive actions

  • Upgrade to versions 2.23.6, 2.22.5, or 2.20.18
  • Inventory checks for affected versions
  • Verify connection security to WebDAV/DavEx servers
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The CVE record and source item provide details on the vulnerability in Apache Jackrabbit's WebDAV/Davex client. The issue allows for arbitrary class instantiation from the client's classpath, potentially leading to file creation or truncation.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-92415 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-92415

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-92415 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-92415

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.