THE Apache Software Foundation has patched two critical vulnerabilities in the Jackrabbit WebDAV components. The more serious issue, CVE-2026-92414, carries a CVSSv4 score of 9.3 and allows an unauthenticated attacker to hijack a cached logged-in session by deriving and attaching a valid WebDAV lock or related token to a request with no credential check. The advisory notes these tokens are derivable, enabling session takeover.
A second flaw, CVE-2026-92415, rated 6.9, affects the DavEx/WebDAV client and could let a malicious server or a man-in-the-middle intercept and force the client to load arbitrary classes, potentially leading to arbitrary file creation or truncation. Only applications using jackrabbit-spi2dav to reach a remote repository are affected.
Both issues affect Apache Jackrabbit releases 2.23.0 through 2.23.5, 2.22.0 through 2.22.4, and 2.20.0 through 2.20.17. The recommended mitigations are to upgrade to Jackrabbit 2.23.6, 2.22.5, or 2.20.18, with fixed builds available on the Apache Jackrabbit downloads page. Until upgrades are applied, administrators are advised to avoid exposing the WebDAV server to untrusted networks and to use TLS for client connections to remote repositories.
The article notes that exploitation status is unknown and no public proof-of-concept has been confirmed, emphasising the importance of applying the patches promptly while monitoring vendor advisories.