SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-66391

MEDIUM · CVSS 6.5 EPSS 0.40%

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

Apache Wicket versions 9.0.0 to 9.23.0 and 10.0.0 to 10.9.0 are vulnerable due to insufficient randomness in value generation, leading to potential protection mechanism failures. This vulnerability could allow attackers to predict or manipulate session tokens, compromising application security. Organizations using affected versions should prioritize upgrading to version 10.10.0 to mitigate this risk.

CVE
CVE-2026-66391
Severity
MEDIUM
CVSS
6.5
EPSS
0.40%
Apache

Original NVD Description

Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability in Apache Wicket. This issue affects Apache Wicket: from 9.0.0 through 9.23.0, from 10.0.0 through 10.9.0. Users are recommended to upgrade to version 10.10.0, which fixes the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)