Advisory CVE-2026-92415 describes a medium-severity vulnerability in the Apache Jackrabbit WebDAV/DavEx client. The issue involves using external input to select classes or code. According to the text received, the use of Class.forName and of a String constructor happens based on error responses controlled by the server. A malicious WebDAV/DavEx server, or an attacker able to influence the response, could exploit this path. The CVSS 4.0 vector given is AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/S:N, with a score of 6.9. It indicates network exploitation, no authentication and no user interaction, with low integrity impact and no declared impact on confidentiality or availability.
The affected versions listed are Apache Jackrabbit 2.23.0 through 2.23.5, 2.22.0 through 2.22.4, and 2.20.0 through 2.20.17. The text was machine-translated from the oss-sec feed and was published by the maintainer on 7 October. The translation may not preserve technical nuances. To verify the information, consult the original advisory on the oss-sec list referenced in the record, and confirm the fixed versions and official Apache project guidance. This summary does not state a fixed version, so do not assume one from it.
The relevance for an organization lies in inventory and updating. If your team uses Jackrabbit libraries in WebDAV clients or integrations, identify the installed versions and compare them with the affected ranges.