[NEW] [high] Apache Wicket: Multiple vulnerabilities
An attacker can exploit multiple vulnerabilities in Apache Wicket to bypass security measures, manipulate or disclose data, or conduct Cross-Site Scripting attacks.
CSIRTS triage
- What
- Multiple vulnerabilities in Apache Wicket enabling security bypass, data manipulation, information disclosure, and cross-site scripting.
- Who is affected
- Web applications built with Apache Wicket.
- Urgency
- High; multiple attack vectors affecting data integrity, confidentiality, and XSS protection in web applications.
- Action
- Apply available Apache Wicket security patches; review and upgrade affected applications to latest patched version.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Wicket
Get an email when a new Wicket advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3091
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-70449 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-71257 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-71378 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-75802 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-76982 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-76983 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-76984 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-76985 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-76986 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- mediumCVE-2026-76986: Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicke…nvd
- mediumCVE-2026-76985: Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicke…nvd
- mediumCVE-2026-76984: Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicke…nvd
- mediumCVE-2026-76983: Improper neutralization of input during web page generation in Apache Wicket. The tag is provi…nvd
- mediumCVE-2026-76982: Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicke…nvd
- mediumCVE-2026-75802: AjaxEditableChoiceLabel in wicket-extensions, when constructed with a non-null IChoiceRenderer…nvd
- mediumCVE-2026-71378: ResourceIsolationRequestCycleListener protects a Wicket application against cross-site request…nvd
- highCVE-2026-71257: Apache Wicket enforces the upload limits configured on a form or upload field while parsing a …nvd
- mediumCVE-2026-70449: Improper validation of resource URL attributes in Apache Wicket allows an unauthenticated remo…nvd
Recent advisories for Apache Wicket
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumCVE-2026-76986: Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicke…nvd · 2026-08-31
- mediumCVE-2026-76985: Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicke…nvd · 2026-08-31
- mediumCVE-2026-76984: Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicke…nvd · 2026-08-31
- mediumCVE-2026-76983: Improper neutralization of input during web page generation in Apache Wicket. The tag is provi…nvd · 2026-08-31
- mediumCVE-2026-76982: Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicke…nvd · 2026-08-31
- highCVE-2026-71257: Apache Wicket enforces the upload limits configured on a form or upload field while parsing a …nvd · 2026-08-31
More from CERT-Bund (BSI) Security Advisories
- medium[UPDATE] [mittel] ILIAS: Mehrere Schwachstellen2026-09-08
- high[UPDATE] [hoch] Mozilla Firefox, Firefox ESR und Thunderbird: Mehrere Schwachstellen2026-09-07
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff2026-09-07
- high[UPDATE] [hoch] Google Chrome: Mehrere Schwachstellen2026-09-07
- high[UPDATE] [hoch] Mozilla Firefox und Thunderbird: Mehrere Schwachstellen2026-09-07