PatchSiren cyber security CVE debrief
CVE-2026-48047 xwiki CVE debrief
A potential path traversal vulnerability in XWiki Platform WebJars API allows an attacker with admin access to a subwiki to write arbitrary files by installing a malicious WebJar extension. The attacker must publish the malicious extension in a configured extension repository. Patched in XWiki 16.10.17, 17.4.9, 17.10.3, and 18.0.0RC1. This vulnerability could allow attackers to override configuration files and set the superadmin password, emphasizing the need for defenders to verify exposure and apply patches promptly.
- Vendor
- xwiki
- Product
- xwiki-platform
- CVSS
- MEDIUM 5.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-07
- Original CVE updated
- 2026-09-18
- Advisory published
- 2026-08-07
- Advisory updated
- 2026-09-18
Who should care
Defenders responsible for XWiki instances, especially those with admin access granted to users or scripts, should assess exposure and apply patches or workarounds to prevent potential path traversal attacks.
Why it matters
Defenders should prioritize verifying exposure in XWiki instances, especially those with admin access granted to users or scripts, and apply patches or workarounds to prevent potential path traversal attacks. The attack requires admin access to a subwiki and publication of a malicious extension in a configured repository. Patched versions are available, but the exact scope of affected instances remains unknown.
- Potential arbitrary file writing with admin access.
- Possible configuration file override and superadmin password reset.
- Required verification of XWiki instance exposure and patch application.
- Potential for malicious extension installation and exploitation.
Technical summary
The XWiki Platform WebJars API is vulnerable to a path traversal attack, allowing an attacker with admin access to a subwiki to write arbitrary files by installing a malicious WebJar extension. The attacker must publish the malicious extension in a configured extension repository. This vulnerability has been patched in XWiki 16.10.17, 17.4.9, 17.10.3, and 18.0.0RC1. The attack requires careful planning and execution, including gaining admin access to a subwiki and publishing a malicious extension, highlighting the importance of restricting admin access and monitoring extension installations.
Defensive priority
Defenders should prioritize verifying exposure in XWiki instances, especially those with admin access granted to users or scripts, and apply patches or workarounds.
Recommended defensive actions
- Verify XWiki instance exposure, especially for admin access granted to users or scripts.
- Apply patches or workarounds to prevent potential path traversal attacks.
- Monitor extension repository configurations for suspicious activity.
- Restrict admin access to subwikis and extension installation.
- Implement additional logging and monitoring for WebJar extension installations.
- Conduct regular security audits to identify and address potential vulnerabilities.
- Review and update incident response plans to include procedures for handling potential path traversal attacks.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, affected versions, and patched versions. However, the exact scope of affected instances and the number of potential targets remain unknown.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-48047 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-48047
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-48047 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-48047
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/xwiki/xwiki-platform/commit/9f747fcd3200259a1de51957d3f5f6acc8e3816c
-
Source reference
Unverified legacy reference
URL: https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-vgwr-23fq-pr7g
-
Source reference
Unverified legacy reference
URL: https://jira.xwiki.org/browse/XWIKI-23902
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.