CVE-2026-5795

Source
https://cve.org/CVERecord?id=CVE-2026-5795
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-5795.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-5795
Aliases
Downstream
Related
Published
2026-04-08T13:32:28.935Z
Modified
2026-05-28T04:12:05.531205123Z
Severity
  • 7.4 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
[none]
Details

In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable.

Upon returning from the initial checks, there are conditions that cause an early return from the JASPIAuthenticator code without clearing those ThreadLocals.

A subsequent request using the same thread inherits the ThreadLocal values, leading to a broken access control and privilege escalation.

Database specific
{
    "cwe_ids": [
        "CWE-226",
        "CWE-287"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/5xxx/CVE-2026-5795.json",
    "cna_assigner": "eclipse",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "11.0.0"
                },
                {
                    "last_affected": "11.0.28"
                },
                {
                    "introduced": "10.0.0"
                },
                {
                    "last_affected": "10.0.28"
                },
                {
                    "introduced": "9.4.0"
                },
                {
                    "last_affected": "9.4.60"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/jetty/jetty.project

Affected ranges

Type
GIT
Repo
https://github.com/jetty/jetty.project
Events

Affected versions

jetty-12.*
jetty-12.0.0
jetty-12.0.0x
jetty-12.0.1
jetty-12.0.10
jetty-12.0.11
jetty-12.0.12
jetty-12.0.13
jetty-12.0.14
jetty-12.0.15
jetty-12.0.16
jetty-12.0.17
jetty-12.0.18
jetty-12.0.19
jetty-12.0.2
jetty-12.0.20
jetty-12.0.21
jetty-12.0.22
jetty-12.0.23
jetty-12.0.24
jetty-12.0.25
jetty-12.0.26
jetty-12.0.27
jetty-12.0.28
jetty-12.0.29
jetty-12.0.3
jetty-12.0.30
jetty-12.0.31
jetty-12.0.32
jetty-12.0.33
jetty-12.0.35
jetty-12.0.4
jetty-12.0.5
jetty-12.0.6
jetty-12.0.7
jetty-12.0.8
jetty-12.0.9
jetty-12.1.0
jetty-12.1.0.alpha0
jetty-12.1.0.alpha1
jetty-12.1.0.alpha2
jetty-12.1.0.beta0
jetty-12.1.0.beta1
jetty-12.1.0.beta2
jetty-12.1.0.beta3
jetty-12.1.1
jetty-12.1.2
jetty-12.1.3
jetty-12.1.4
jetty-12.1.5
jetty-12.1.6
jetty-12.1.7
jetty-12.1.9

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-5795.json"