PatchSiren cyber security CVE debrief
CVE-2026-92415 Apache Software Foundation CVE debrief
Apache Jackrabbit's WebDAV/Davex client is vulnerable to an Externally-Controlled Input to Select Classes or Code issue. A malicious WebDAV/DavEx server or an attacker intercepting the connection can cause the client to instantiate arbitrary classes from its classpath, potentially leading to arbitrary file creation or truncation. This issue affects applications using jackrabbit-spi2dav or jackrabbit-jcr2dav to connect to a remote repository. Only applications that use jackrabbit-spi2dav (directly or through jackrabbit-jcr2dav) to connect to a remote repository are affected. Jackrabbit servers are not affected.
- Vendor
- Apache Software Foundation
- Product
- Apache Jackrabbit
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders of systems using Apache Jackrabbit's WebDAV/Davex client, specifically those connecting to remote repositories using jackrabbit-spi2dav or jackrabbit-jcr2dav, should assess exposure and prioritize remediation.
Why it matters
Defenders should care due to the potential for arbitrary file creation or truncation, risk of unauthorized data modification, need for inventory checks and version verification, and priority on upgrading to fixed versions.
- Potential for arbitrary file creation or truncation
- Risk of unauthorized data modification
- Need for inventory checks and version verification
- Priority on upgrading to fixed versions
Technical summary
The vulnerability in Apache Jackrabbit's WebDAV/Davex client allows a malicious server or intercepted connection to cause the client to instantiate arbitrary classes from its classpath. This can lead to arbitrary file creation or truncation. Affected versions include 2.23.0 through 2.23.5, 2.22.0 through 2.22.4, and 2.20.0 through 2.20.17. The issue arises from the client's handling of server-controlled error bodies, which can lead to unsafe reflection on wire data. Defenders should prioritize upgrading to fixed versions and perform inventory checks.
Defensive priority
Defenders should prioritize upgrading to versions 2.23.6, 2.22.5, or 2.20.18. Inventory checks are necessary to identify affected versions 2.23.0 through 2.23.5, 2.22.0 through 2.22.4, and 2.20.0 through 2.20.17.
Recommended defensive actions
- Upgrade to versions 2.23.6, 2.22.5, or 2.20.18
- Inventory checks for affected versions
- Verify connection security to WebDAV/DavEx servers
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The CVE record and source item provide details on the vulnerability in Apache Jackrabbit's WebDAV/Davex client. The issue allows for arbitrary class instantiation from the client's classpath, potentially leading to file creation or truncation.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-92415 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-92415
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-92415 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-92415
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Apache Jackrabbit: DavEx client runs Class.forName + (String)-constructor on server-controlled e
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/92xxx/CVE-2026-92415.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://lists.apache.org/thread.html/hcrxm4jp1mtk56xb8p1dtryz7hl08kmr
Supplemental source - vendor-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.