CVE-2026-76982
Received Received - Intake

Cross-Site Scripting in Apache Wicket Button Component

Vulnerability report for CVE-2026-76982, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-31

Last updated on: 2026-08-31

Assigner: Apache Software Foundation

Description

Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.markup.html.form.Button clears the escape-model-strings flag in its constructor, so that the value attribute it writes is not encoded twice β€” ComponentTag already encodes attribute values when it writes the tag. That reasoning holds only for the attribute. When the component is attached to a <button> element rather than an <input>, it writes its model object into the element body instead, and nothing encodes an element body, so markup in the model is rendered as markup. An application is affected where it renders a Button on a <button> element and that button's model holds data an attacker can influence. Wicket cannot determine where a model value comes from, so whether it reaches the page from a request or from storage is a property of the application. The subclasses that inherit this constructor β€” AjaxButton, AjaxFallbackButton and WizardButton β€” are affected on the same terms. As a workaround, calling setEscapeModelStrings(true) on a button that renders as a <button> element escapes the body correctly, and does not cause double encoding, because the value attribute is written only for <input> elements. This issue affects Apache Wicket: from 8.0.0 through 8.18.0, from 9.0.0 through 9.23.0, from 10.0.0 through 10.10.0. Older, unsupported releases from 6.25.0 and 7.5.0 onwards are also affected. Users are recommended to upgrade to version 8.19.0, 9.24.0 or 10.11.0, which fix the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-31
Last Modified
2026-08-31
Generated
2026-08-31
AI Q&A
2026-08-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 10 associated CPEs
Vendor Product Version / Range
apache wicket From 8.0.0 (inc) to 8.18.0 (inc)
apache wicket From 9.0.0 (inc) to 9.23.0 (inc)
apache wicket From 10.0.0 (inc) to 10.10.0 (inc)
apache wicket 6.25.0
apache wicket 7.5.0
apache wicket 8.19.0
apache wicket 9.24.0
apache wicket 10.11.0
apache wicket From 6.25.0 (inc)
apache wicket From 7.5.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves improper input neutralization in Apache Wicket, where the Button component does not escape model strings when rendering on a <button> element. This allows attackers to inject malicious markup into the page body, which is then rendered as executable code instead of plain text.

Detection Guidance

To detect this vulnerability, inspect Apache Wicket applications for Button components rendering on <button> elements where model data may be user-controlled. Check if setEscapeModelStrings(true) is called on such buttons. Review application logs for unexpected markup rendering in button bodies.

Impact Analysis

An attacker could exploit this to execute arbitrary scripts in a user's browser, leading to session hijacking, data theft, or defacement of the application. It affects applications using vulnerable Wicket versions where Button models are influenced by user input.

Compliance Impact

This vulnerability could potentially violate compliance with GDPR and HIPAA by enabling cross-site scripting (XSS) attacks. If an attacker injects malicious markup via user-controlled data in a Button component, it may lead to unauthorized data access or manipulation, compromising confidentiality and integrity of sensitive information.

Mitigation Strategies

Upgrade Apache Wicket to version 8.19.0, 9.24.0, or 10.11.0 or later. As a temporary workaround, call setEscapeModelStrings(true) on affected Button components rendering on <button> elements.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76982. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart