PT-2026-80738 · Xwiki · Xwiki
CVE-2026-53966
·
Published
2026-06-11
·
Updated
2026-08-19
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
XWiki versions prior to 16.10.17
XWiki versions prior to 17.4.10
XWiki versions prior to 17.10.4
XWiki versions prior to 18.1.0
Description
Users with page editing permissions can utilize the Live Data edit REST API to modify page rights, enabling them to obtain script rights. This allows the execution of potentially dangerous Velocity scripts and the delivery of unfiltered HTML and JavaScript to clients. Additionally, security checks implemented as listeners to
UserUpdatingDocumentEvent and similar User... events can be bypassed.Recommendations
Update to version 16.10.17.
Update to version 17.4.10.
Update to version 17.10.4.
Update to version 18.1.0.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xwiki