Input Manipulation Risk in Apache Wicket Affects Multiple Versions
CVE-2026-76986

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
31 August 2026

What is CVE-2026-76986?

A vulnerability exists in Apache Wicket where improper neutralization of input during web page generation can lead to security risks. Specifically, in the AbstractSingleSelectChoice class, the default option body may not be properly escaped when no choice is selected. If a web application overrides certain methods and returns user-influenced values, attackers may exploit this flaw. To mitigate this risk, it is recommended to escape values in custom overrides. Users should upgrade to versions 8.19.0, 9.24.0, or 10.11.0 to address this vulnerability.

Affected Version(s)

Apache Wicket 8.0.0 <= 8.18.0

Apache Wicket 9.0.0 <= 9.23.0

Apache Wicket 10.0.0 <= 10.10.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Emond Papegaaij
.