PT-2026-31308 · Eclipse · Eclipse Jetty

Published

2026-04-08

·

Updated

2026-04-18

·

CVE-2026-5795

CVSS v3.1

7.4

High

AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Eclipse Jetty (affected versions not specified)
Description Eclipse Jetty's JASPIAuthenticator class sets two ThreadLocal variables during authentication checks. Under certain conditions, the code returns early without clearing these ThreadLocal variables. A subsequent request using the same thread inherits these values, resulting in broken access control and potential privilege escalation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2026-5795
GHSA-GC59-R5JQ-98QW
GHSA-R7P8-XQ5M-436C
OPENSUSE-SU-2026:10574-1

Affected Products

Eclipse Jetty