Apache Wicket Session Fixation Vulnerability

Vulnerability

A session fixation vulnerability has been identified in Apache Wicket versions 8.0.0 through 8.17.0, 9.0.0, and 10.0.0 through 10.8.0. The issue arises from the missing invocation of the Servlet HTTP web request method 'changeSessionId' after session binding, which can be exploited to fixate a user's session.

Impact

Exploitation of this vulnerability allows for session fixation attacks, where an attacker can hijack a user's session by forcing the user to authenticate with a session ID known to the attacker.

Remediation

Users are advised to upgrade to Apache Wicket version 10.9.0, which addresses this vulnerability.

Added: May 6, 2026, 11:18 AM
Updated: May 6, 2026, 11:18 AM

Vulnerability Rating

Custom Algorithm
spread
4.2
impact
1.3
exploitability
4.2
remediation
7.7
relevance
7.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.