CVE-2026-76985

MEDIUM CVSS 4.0: 5.1 EPSS 0.50%
Updated Sep 01, 2026
Apache
Parameter Value
CVSS 5.1 (MEDIUM)
Affected Versions 10.0.0 — 9.24.0
Fixed In 8.19.0
Type CWE-79 (Cross-Site Scripting (XSS))
Vendor Apache
Public PoC No

Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.extensions.markup.html.form.palette.component.AbstractOptions, which renders the two option lists of a Palette, escapes the id and the display value of each option according to the escape-model-strings setting, and wrote the attribute names and values returned by getAdditionalAttributes into the <option> tag as they came. An application is affected where it overrides Palette.getAdditionalAttributesForChoices, Palette.getAdditionalAttributesForSelection or AbstractOptions.getAdditionalAttributes and returns a value holding data an attacker can influence. These methods return null by default, so an application that does not override them is not affected.

As a workaround, escape the values in the override. This issue affects Apache Wicket: from 8.0.0 through 8.18.0, from 9.0.0 through 9.23.0, from 10.0.0 through 10.10.0. Older, unsupported releases from 1.4.0 onwards are also affected.

Users are recommended to upgrade to version 8.19.0, 9.24.0 or 10.11.0, which fix the issue.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
Low
Basic privileges needed
User Interaction
Passive
Minimal interaction

Impact Assessment

Confidentiality
None
No data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v4.0

Vulnerable Products 3

Configuration From (including) Up to (excluding)
Apache Wicket
cpe:2.3:a:apache:wicket:*:*:*:*:*:*:*:*
8.0.0 8.19.0
Apache Wicket
cpe:2.3:a:apache:wicket:*:*:*:*:*:*:*:*
9.0.0 9.24.0
Apache Wicket
cpe:2.3:a:apache:wicket:*:*:*:*:*:*:*:*
10.0.0 10.11.0