Input Manipulation Risk in Apache Wicket Affects Multiple Versions
CVE-2026-76986
Currently unrated
What is CVE-2026-76986?
A vulnerability exists in Apache Wicket where improper neutralization of input during web page generation can lead to security risks. Specifically, in the AbstractSingleSelectChoice class, the default option body may not be properly escaped when no choice is selected. If a web application overrides certain methods and returns user-influenced values, attackers may exploit this flaw. To mitigate this risk, it is recommended to escape values in custom overrides. Users should upgrade to versions 8.19.0, 9.24.0, or 10.11.0 to address this vulnerability.
Affected Version(s)
Apache Wicket 8.0.0 <= 8.18.0
Apache Wicket 9.0.0 <= 9.23.0
Apache Wicket 10.0.0 <= 10.10.0