logo

Triple Critical Threat: Apache Wicket Patch Fixes Path Traversal, Session Hijacking, and Resource Bypass

ID: a063b9b6-a1ab-5493-88a6-6ec85e551d98

STIX ID: report--a063b9b6-a1ab-5493-88a6-6ec85e551d98

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-05-07

Date Updated: 2026-05-07

Author: Ddos

...
...

Apache Wicket published an urgent security bulletin reporting four vulnerabilities — three rated Critical (unauthenticated path traversal allowing arbitrary file read/write, session fixation enabling session hijacking, and a PackageResourceGuard bypass) and one Important (cross-site scripting). The advisory affects 8.x, 9.x and 10.x releases and directs users to upgrade to version 10.9.0 immediately to mitigate potential unauthenticated attacks and information disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.