CVE-2026-61899

7.5

Apache · Apache Tapestry

A vulnerability in the tapestry-core component of Apache Tapestry 5 allows for the unauthorized exposure of sensitive information to unauthenticated actors.

Executive summary

A high-severity information disclosure vulnerability in Apache Tapestry 5 enables unauthenticated remote attackers to access sensitive system data.

Vulnerability

This is an exposure of sensitive information to an unauthorized actor (CWE-200) within the tapestry-core module. The vulnerability permits an unauthenticated attacker to gain access to information that should be protected.

Business impact

With a CVSS score of 7.5, this vulnerability represents a significant risk to application security. Successful exploitation could allow attackers to harvest sensitive data, potentially leading to further reconnaissance or unauthorized access to backend systems.

Remediation

Immediate Action: Update Apache Tapestry to version 5.9.1 or later to resolve the information disclosure flaw.

Proactive Monitoring: Review application access logs for unusual patterns of data retrieval or requests targeting sensitive system files and configuration endpoints.

Compensating Controls: Implement strict access control lists at the network or application level to limit exposure of the tapestry-core components to untrusted networks.

Exploitation status

Public Exploit Available: false

Analyst recommendation

Organizations utilizing Apache Tapestry should audit their environments to identify all instances within the vulnerable version range. Applying the update to version 5.9.1 is the only effective way to remediate this information disclosure risk.

More Apache CVEs