Cross-site scripting in Apache Wicket - CVE-2026-75802

 

Cross-site scripting in Apache Wicket - CVE-2026-75802

Published: August 31, 2026


Vulnerability identifier: #VU146326
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2026-75802
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary script in the victim's browser.

The vulnerability exists due to improper neutralization of input during web page generation in AjaxEditableChoiceLabel, AjaxEditableLabel, and AjaxEditableMultiLineLabel when rendering attacker-influenced label values. A remote attacker can supply crafted choice, model, or null-label data to execute arbitrary script in the victim's browser.

Only the label rendering is affected; the dropdown editor escapes the same renderer value when displaying it as an option. Applications are affected for empty-model rendering only if defaultNullLabel() is overridden to return an attacker-influenced value.


Affected software

Apache Wicket

How to mitigate CVE-2026-75802

Install security update from vendor's website.

Apache Wicket - addressed in versions 8.19.0, 9.24.0, 10.11.0

External References

Related Security Bulletins