CVE-2026-28811CWE-1295

CVE-2026-28811

High · published July 30, 2026

CVSS v3.1
7.5
EPSS
0%
Percentile
39.5
In the wild
Unconfirmed
What it is

Debug Messages Revealing Unnecessary Information in Apache JSPWiki up to 2.12.3.

Users are recommended to upgrade to version 2.12.4, which fixes this issue.

The record
Technical detail
CVSS v3.1
7.5 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00477 · 39.5th percentile
Weakness
CWE-1295 · Debug Messages Revealing Unnecessary Information
Published
2026-07-30T20:17Z
Affected products (1)
ProductVersionsFixed in
apache/jspwiki< 2.12.42.12.4
References (3)
EPSS history
Timeline
  • 30 JUL 15:51Z
    Apache JSPWiki: Error Handling - Reveals Error Details
    cvelistv5