Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Wicket.

This issue affects Apache Wicket: from 8.0.0 through 8.17.0, from 9.0.0 through 9.22.0, from 10.0.0 through 10.8.0.

Users are recommended to upgrade to version 10.9.0, which fixes the issue.
Published: 2026-05-06
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows an attacker to craft URLs that bypass Apache Wicket's PackageResourceGuard, leading to the exposure of sensitive application resources. The flaw is a case of insufficient input validation that permits unauthorized access to protected files, classified as CWE-200. An attacker could gain read access to files or resources that should be restricted, compromising confidentiality and potentially enabling further exploitation.

Affected Systems

The affected product is Apache Wicket, distributed by the Apache Software Foundation. Versions from 8.0.0 through 8.17.0, from 9.0.0 through 9.22.0, and from 10.0.0 through 10.8.0 are vulnerable. Users are advised to upgrade to version 10.9.0 or later, which contains the fix for this issue.

Risk and Exploitability

EPSS score is < 1%, indicating a very low likelihood of public exploitation and the vulnerability is not listed on CISA's KEV catalog. Nevertheless, the CVSS score is 7.5, classifying the vulnerability as high severity and suggesting that the ability to read restricted resources poses a moderate to high risk to confidentiality. The attack can be carried out remotely by sending a crafted URL to a vulnerable Wicket application, without any authentication. Consequently, organizations running the affected versions should treat this as a priority patching issue.

Generated by OpenCVE AI on May 6, 2026 at 16:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Wicket to version 10.9.0 or later to apply the vendor patch that re-enforces PackageResourceGuard enforcement.
  • Verify that the default PackageResourceGuard settings remain enabled and that no custom URL handlers bypass the guard.
  • For environments that cannot immediately upgrade, restrict access to sensitive resources using web server ACLs, deny direct URL access to file paths, or implement additional application-level checks to validate request parameters.

Generated by OpenCVE AI on May 6, 2026 at 16:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-jvv4-8wxx-m5r6 Apache Wicket has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
History

Wed, 06 May 2026 20:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:apache:wicket:*:*:*:*:*:*:*:*

Wed, 06 May 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 06 May 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache wicket
Vendors & Products Apache
Apache wicket

Wed, 06 May 2026 10:30:00 +0000

Type Values Removed Values Added
References

Wed, 06 May 2026 09:30:00 +0000

Type Values Removed Values Added
Description Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Wicket. This issue affects Apache Wicket: from 8.0.0 through 8.17.0, from 9.0.0 through 9.22.0, from 10.0.0 through 10.8.0. Users are recommended to upgrade to version 10.9.0, which fixes the issue.
Title Apache Wicket: crafted URLs can bypass PackageResourceGuard
Weaknesses CWE-200
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-05-06T13:58:50.550Z

Reserved: 2026-05-01T18:38:59.813Z

Link: CVE-2026-43646

cve-icon Vulnrichment

Updated: 2026-05-06T09:51:14.174Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-06T10:16:26.037

Modified: 2026-05-06T20:29:51.313

Link: CVE-2026-43646

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-06T16:30:06Z

Weaknesses