PT-2026-37375 · Apache · Apache Wicket

Pedro Henrique Oliveira Dos Santos

·

Published

2026-05-06

·

Updated

2026-05-07

·

CVE-2026-40010

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache Wicket versions 8.0.0 through 8.17.0 Apache Wicket version 9.0.0 Apache Wicket versions 10.0.0 through 10.8.0
Description A session fixation attack is possible due to the missing invocation of the Servlet http web request method changeSessionId() after session binding.
Recommendations Upgrade to version 10.9.0.

Fix

Session Fixation

Weakness Enumeration

Related Identifiers

CVE-2026-40010
GHSA-QPJW-P3JG-59J6

Affected Products

Apache Wicket