Advisory CVE-2026-92414 was published by Julian Reschke on the oss-sec list on October 7, 2026 and assigns a CVSS 4.0 score of 9.3, rated critical. The stated vector indicates network attack, low complexity, no privileges and no user interaction, with high impact on confidentiality and integrity and no declared impact on availability. According to the text, the WebDAV server associates a cached authenticated session with any request, which describes session fixation and cross-user session reuse. Affected versions are Apache Jackrabbit 2.23.0 through 2.23.5, 2.22.0 through 2.22.4, and 2.20.0 through 2.20.17. The material consulted is an automatic translation of an oss-sec feed item and the available excerpt is truncated, so the full technical description, fix details and mitigation recommendations must be read in the original advisory. The relevance to Rota Nacional is indirect: the platform does not run or patch Jackrabbit, and no Rota capability resolves this flaw. Whoever operates the software should compare the installed version with the affected list and apply the update indicated by the project. If the team uses AI to study the advisory, do not paste tokens, cookies, keys, session logs or configurations with real identifiers. Rota detection covers personal data such as CPF, CNPJ, e-mail, phone and names, but technical secrets must be removed by the user before sending.
Cyber ·
CVE-2026-92414: critical Apache Jackrabbit flaw allows reuse of cached sessions
Advisory dated October 7, 2026 describes a critical flaw (CVSS 4.0: 9.3) in the Apache Jackrabbit WebDAV server that allows reusing cached authenticated sessions without prior authentication, with a risk of access across users.
Rota Nacional
Bring privacy into your workflow.
30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.