Cross-site scripting in Apache Wicket - CVE-2026-76984

 

Cross-site scripting in Apache Wicket - CVE-2026-76984

Published: August 31, 2026


Vulnerability identifier: #VU146323
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2026-76984
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary script code in the victim's browser.

The vulnerability exists due to improper neutralization of input during web page generation in org.apache.wicket.markup.head.MetaDataHeaderItem when generating and tags with attacker-influenced attribute values. A remote attacker can supply a crafted attribute value containing a double quote to inject additional attributes and execute arbitrary script code in the victim's browser.

An application is affected only if it passes attacker-influenced data to addTagAttribute or the forMetaTag or forLinkTag factory methods. A value may be provided through an IModel rather than as a literal.


Affected software

Apache Wicket

How to mitigate CVE-2026-76984

Install security update from vendor's website.

Apache Wicket - addressed in versions 8.19.0, 9.24.0, 10.11.0

External References

Related Security Bulletins