PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-48047 xwiki CVE debrief

A potential path traversal vulnerability in XWiki Platform WebJars API allows an attacker with admin access to a subwiki to write arbitrary files by installing a malicious WebJar extension. The attacker must publish the malicious extension in a configured extension repository. Patched in XWiki 16.10.17, 17.4.9, 17.10.3, and 18.0.0RC1. This vulnerability could allow attackers to override configuration files and set the superadmin password, emphasizing the need for defenders to verify exposure and apply patches promptly.

Vendor
xwiki
Product
xwiki-platform
CVSS
MEDIUM 5.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-07
Original CVE updated
2026-09-18
Advisory published
2026-08-07
Advisory updated
2026-09-18

Who should care

Defenders responsible for XWiki instances, especially those with admin access granted to users or scripts, should assess exposure and apply patches or workarounds to prevent potential path traversal attacks.

Why it matters

Defenders should prioritize verifying exposure in XWiki instances, especially those with admin access granted to users or scripts, and apply patches or workarounds to prevent potential path traversal attacks. The attack requires admin access to a subwiki and publication of a malicious extension in a configured repository. Patched versions are available, but the exact scope of affected instances remains unknown.

  • Potential arbitrary file writing with admin access.
  • Possible configuration file override and superadmin password reset.
  • Required verification of XWiki instance exposure and patch application.
  • Potential for malicious extension installation and exploitation.

Technical summary

The XWiki Platform WebJars API is vulnerable to a path traversal attack, allowing an attacker with admin access to a subwiki to write arbitrary files by installing a malicious WebJar extension. The attacker must publish the malicious extension in a configured extension repository. This vulnerability has been patched in XWiki 16.10.17, 17.4.9, 17.10.3, and 18.0.0RC1. The attack requires careful planning and execution, including gaining admin access to a subwiki and publishing a malicious extension, highlighting the importance of restricting admin access and monitoring extension installations.

Defensive priority

Defenders should prioritize verifying exposure in XWiki instances, especially those with admin access granted to users or scripts, and apply patches or workarounds.

Recommended defensive actions

  • Verify XWiki instance exposure, especially for admin access granted to users or scripts.
  • Apply patches or workarounds to prevent potential path traversal attacks.
  • Monitor extension repository configurations for suspicious activity.
  • Restrict admin access to subwikis and extension installation.
  • Implement additional logging and monitoring for WebJar extension installations.
  • Conduct regular security audits to identify and address potential vulnerabilities.
  • Review and update incident response plans to include procedures for handling potential path traversal attacks.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, affected versions, and patched versions. However, the exact scope of affected instances and the number of potential targets remain unknown.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-48047 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-48047

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-48047 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-48047

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.