Insufficient verification of data authenticity in Apache JSPWiki - CVE-2026-28813
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform cross-site request forgery attacks.
The vulnerability exists due to improper access control in JSON responses when exposing sensitive data structures to cross-origin requests. A remote attacker can induce a victim's browser to access crafted content to perform cross-site request forgery attacks.