PatchSiren cyber security CVE debrief
CVE-2026-23734 xwiki CVE debrief
CVE-2026-23734 is a critical path traversal issue in XWiki Platform that can let an attacker read configuration files through crafted ssx and jsx resource requests. The problem was publicly disclosed on 2026-05-20 and is patched in 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17.
- Vendor
- xwiki
- Product
- xwiki-commons
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-20
- Original CVE updated
- 2026-07-23
- Advisory published
- 2026-05-20
- Advisory updated
- 2026-07-23
Who should care
Administrators and operators of XWiki Platform instances, especially anyone exposing ssx or jsx endpoints to untrusted networks. Security teams should pay particular attention if XWiki configuration files may contain secrets, database credentials, or other sensitive deployment details.
Technical summary
According to the NVD record and linked GitHub Security Advisory, versions prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17 allow path traversal via the resources parameter on ssx and jsx endpoints when leading slashes are used. The example request shown in the description demonstrates that a crafted resource path can reach WEB-INF/xwiki.cfg, enabling unauthorized read access to configuration files. The advisory maps the weakness to CWE-23 (Relative Path Traversal).
Defensive priority
Urgent. The CVSS 9.3 Critical rating and the ability to read configuration files justify immediate patching and exposure review, even if no active exploitation is known from the provided corpus.
Recommended defensive actions
- Upgrade XWiki Platform to a fixed release: 18.1.0-rc-1, 17.10.3, 17.4.9, or 16.10.17, depending on your branch.
- Restrict network access to XWiki administrative and rendering endpoints, including ssx and jsx, until patched.
- Audit logs for suspicious requests to ssx/jsx endpoints that use the resources parameter with traversal patterns or leading slashes.
- Review whether exposed configuration files may contain credentials, tokens, or other secrets, and rotate any sensitive values if exposure is suspected.
- Validate that reverse proxies, WAF rules, and application routing do not unintentionally broaden access to internal XWiki paths.
Evidence notes
The vulnerability description in the NVD record states that XWiki Platform versions before the listed fixed releases allow configuration-file read access through crafted ssx/jsx resource URLs, leading to path traversal. The GitHub Security Advisory reference and the linked XWiki commit support that a code-level fix was released. The Jira ticket reference provides the project-tracked issue context. This summary stays within the supplied corpus and official links.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-23734 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-23734
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-23734 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-23734
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/xwiki/xwiki-commons/commit/a979cafd89f6a9c9c0b9ab19744d672df64429bf
-
Source reference
Unverified legacy reference
URL: https://github.com/xwiki/xwiki-commons/security/advisories/GHSA-xq3r-2qv5-vqqm
-
Source reference
Unverified legacy reference
URL: https://jira.xwiki.org/browse/XCOMMONS-3547
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.