Cross-site scripting in Apache Wicket - CVE-2026-76982

 

Cross-site scripting in Apache Wicket - CVE-2026-76982

Published: August 31, 2026


Vulnerability identifier: #VU146325
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2026-76982
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary script code in the victim's browser.

The vulnerability exists due to improper neutralization of input during web page generation in org.apache.wicket.markup.html.form.Button when rendering a Button component as a <button> element with an attacker-influenced model object. A remote attacker can supply crafted markup in the model value to execute arbitrary script code in the victim's browser.

The issue affects Button and the subclasses AjaxButton, AjaxFallbackButton, and WizardButton when the application renders them as <button> elements instead of <input> elements.


Affected software

Apache Wicket

How to mitigate CVE-2026-76982

Install security update from vendor's website.

Apache Wicket - addressed in versions 8.19.0, 9.24.0, 10.11.0

External References

Related Security Bulletins