CVE-2026-61899
7.5Apache · Apache Tapestry
A vulnerability in the tapestry-core component of Apache Tapestry 5 allows for the unauthorized exposure of sensitive information to unauthenticated actors.
Executive summary
A high-severity information disclosure vulnerability in Apache Tapestry 5 enables unauthenticated remote attackers to access sensitive system data.
Vulnerability
This is an exposure of sensitive information to an unauthorized actor (CWE-200) within the tapestry-core module. The vulnerability permits an unauthenticated attacker to gain access to information that should be protected.
Business impact
With a CVSS score of 7.5, this vulnerability represents a significant risk to application security. Successful exploitation could allow attackers to harvest sensitive data, potentially leading to further reconnaissance or unauthorized access to backend systems.
Remediation
Immediate Action: Update Apache Tapestry to version 5.9.1 or later to resolve the information disclosure flaw.
Proactive Monitoring: Review application access logs for unusual patterns of data retrieval or requests targeting sensitive system files and configuration endpoints.
Compensating Controls: Implement strict access control lists at the network or application level to limit exposure of the tapestry-core components to untrusted networks.
Exploitation status
Public Exploit Available: false
Analyst recommendation
Organizations utilizing Apache Tapestry should audit their environments to identify all instances within the vulnerable version range. Applying the update to version 5.9.1 is the only effective way to remediate this information disclosure risk.