PT-2026-80738 · Xwiki · Xwiki

CVE-2026-53966

·

Published

2026-06-11

·

Updated

2026-08-19

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions XWiki versions prior to 16.10.17 XWiki versions prior to 17.4.10 XWiki versions prior to 17.10.4 XWiki versions prior to 18.1.0
Description Users with page editing permissions can utilize the Live Data edit REST API to modify page rights, enabling them to obtain script rights. This allows the execution of potentially dangerous Velocity scripts and the delivery of unfiltered HTML and JavaScript to clients. Additionally, security checks implemented as listeners to UserUpdatingDocumentEvent and similar User... events can be bypassed.
Recommendations Update to version 16.10.17. Update to version 17.4.10. Update to version 17.10.4. Update to version 18.1.0.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53966
GHSA-45PH-GXXR-GWGW

Affected Products

Xwiki