---
id: CVE-2026-92415
title: >-
  — Use of Externally-Controlled Input to Select Classes or Code vulnerability
  in Apache Jackrabbit's WebDAV/Davex client.


  A malicious WebDAV/DavEx server, or an attacker able to intercept the
  connection, can cause the client to instantia…
summary: >-
  — Use of Externally-Controlled Input to Select Classes or Code vulnerability
  in Apache Jackrabbit's WebDAV/Davex client.


  A malicious WebDAV/DavEx server, or an attacker able to intercept the
  connection, can cause the client to instantia…
severity: medium
cvss: 6.9
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/S:N'
cwe:
  - CWE-470
vendor: Apache Software Foundation
product: 'org.apache.jackrabbit:jackrabbit-spi2dav'
affected:
  - 'org.apache.jackrabbit:jackrabbit-spi2dav >= 2.23.0 <= 2.23.5'
  - 'org.apache.jackrabbit:jackrabbit-spi2dav >= 2.22.0 <= 2.22.4'
  - 'org.apache.jackrabbit:jackrabbit-spi2dav >= 2.20.0 <= 2.20.17'
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T18:17:31.367'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92415'
references:
  - url: 'https://lists.apache.org/thread.html/hcrxm4jp1mtk56xb8p1dtryz7hl08kmr'
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2026/10/07/28'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-07T16:38:22.230Z'
---

## Overview

— Use of Externally-Controlled Input to Select Classes or Code vulnerability in Apache Jackrabbit's WebDAV/Davex client.

A malicious WebDAV/DavEx server, or an attacker able to intercept the connection, can cause the client to instantiate arbitrary classes from its classpath, which can lead to arbitrary file creation or truncation.

Only applications that use jackrabbit-spi2dav (directly or through jackrabbit-jcr2dav) to connect to a remote repository are affected. Jackrabbit servers are not affected.

Category: unsafe reflection on wire data (HIGH).



This issue affects Apache Jackrabbit: from 2.23.0 through 2.23.5, from 2.22.0 through 2.22.4, from 2.20.0 through 2.20.17.



Users are recommended to upgrade to versions 2.23.6, 2.22.5, or 2.20.18 which fix the issue.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
