Sensitive Information in Resource Not Removed Before Reuse in Jetty - CVE-2026-5795
Published: April 11, 2026
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to sensitive information in resource not removed before reuse in JaspiAuthenticator.java when handling certain error or incomplete authentication flows. A remote attacker can trigger a request sequence that leaves residual authentication metadata in ThreadLocal storage to escalate privileges.
A subsequent unprivileged request processed by the same worker thread may inherit residual security roles if a mandatory CallerPrincipalCallback is missing or an exception occurs after a GroupPrincipalCallback has been persisted.
Affected software
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Package Hub 15
Development Tools Module
IBM Cloud Pak for Data System
IBM Sterling Secure Proxy
IBM Sterling External Authentication Server
IBM Sterling Control Center
Operational Decision Manager
Storage Protect Server
jetty-http
jetty-security
jetty-servlet
jetty-io
jetty-util
jetty-util-ajax
jetty-server
jetty-continuation
How to mitigate CVE-2026-5795
IBM Cloud Pak for Data System - update to 8.10.26.07.SP3
IBM Sterling Secure Proxy - update to 6.2.1.2.iFix02
IBM Sterling External Authentication Server - update to 6.1.1.3 iFix01
IBM Sterling Control Center - addressed in versions 6.3.1.0.9, 6.4.1.0.3, 6.4.2.0.4
Storage Protect Server - update to 8.2.2
jetty-http - update to 9.4.58-150200.3.40.1
jetty-security - update to 9.4.58-150200.3.40.1
jetty-servlet - update to 9.4.58-150200.3.40.1
jetty-io - update to 9.4.58-150200.3.40.1
jetty-util - update to 9.4.58-150200.3.40.1
jetty-util-ajax - update to 9.4.58-150200.3.40.1
jetty-server - update to 9.4.58-150200.3.40.1
jetty-continuation - update to 9.4.58-150200.3.40.1
External References
Related Security Bulletins
- Improper authentication in Eclipse Jetty
- SUSE update for jetty-minimal
- IBM Control Center update for Eclipse Jetty
- Multiple vulnerabilities in IBM Operational Decision Manager
- Multiple vulnerabilities in IBM Sterling Secure Proxy
- IBM Storage Protect Server update for Eclipse Jetty
- Multiple vulnerabilities in IBM Sterling External Authentication Server
- Multiple vulnerabilities in IBM Cloud Pak for Data System