Insufficient Random Value Vulnerability in Apache Wicket
CVE-2026-66391

6.5MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
27 July 2026

What is CVE-2026-66391?

A vulnerability in Apache Wicket arises from the use of insufficiently random values, leading to potential weaknesses in the protection mechanisms. This issue affects versions 9.0.0 through 9.23.0 and 10.0.0 through 10.9.0. It is recommended that users upgrade to version 10.10.0 to mitigate this vulnerability effectively.

Affected Version(s)

Apache Wicket 9.0.0 <= 9.23.0

Apache Wicket 10.0.0 <= 10.9.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.