Sensitive Information in Resource Not Removed Before Reuse in Jetty - CVE-2026-5795

 

Sensitive Information in Resource Not Removed Before Reuse in Jetty - CVE-2026-5795

Published: April 11, 2026


Vulnerability identifier: #VU125816
CSH Severity: High
CVSS v4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-5795
CWE-ID: CWE-226
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to sensitive information in resource not removed before reuse in JaspiAuthenticator.java when handling certain error or incomplete authentication flows. A remote attacker can trigger a request sequence that leaves residual authentication metadata in ThreadLocal storage to escalate privileges.

A subsequent unprivileged request processed by the same worker thread may inherit residual security roles if a mandatory CallerPrincipalCallback is missing or an exception occurs after a GroupPrincipalCallback has been persisted.


Affected software

Jetty
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Package Hub 15
Development Tools Module
IBM Cloud Pak for Data System
IBM Sterling Secure Proxy
IBM Sterling External Authentication Server
IBM Sterling Control Center
Operational Decision Manager
Storage Protect Server
jetty-http
jetty-security
jetty-servlet
jetty-io
jetty-util
jetty-util-ajax
jetty-server
jetty-continuation

How to mitigate CVE-2026-5795

Install security update from vendor's website.

Jetty - addressed in versions 12.0.34, 12.1.8
IBM Cloud Pak for Data System - update to 8.10.26.07.SP3
IBM Sterling Secure Proxy - update to 6.2.1.2.iFix02
IBM Sterling External Authentication Server - update to 6.1.1.3 iFix01
IBM Sterling Control Center - addressed in versions 6.3.1.0.9, 6.4.1.0.3, 6.4.2.0.4
Storage Protect Server - update to 8.2.2
jetty-http - update to 9.4.58-150200.3.40.1
jetty-security - update to 9.4.58-150200.3.40.1
jetty-servlet - update to 9.4.58-150200.3.40.1
jetty-io - update to 9.4.58-150200.3.40.1
jetty-util - update to 9.4.58-150200.3.40.1
jetty-util-ajax - update to 9.4.58-150200.3.40.1
jetty-server - update to 9.4.58-150200.3.40.1
jetty-continuation - update to 9.4.58-150200.3.40.1

External References

Related Security Bulletins