PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-48048 xwiki CVE debrief

CVE-2026-48048 debrief based on the supplied source corpus. The XWiki Platform is vulnerable due to an insufficient patch for GHSA-5cf8-vrr8-8hjm, allowing attackers to retrieve password hashes one bit at a time with 768 requests, impacting versions 6.2.1 to 18.0.0RC1, 17.10.13, 17.4.9, and 16.10.17. Defenders should assess exposure and apply patches or workarounds. The vulnerability affects XWiki Platform's LiveTableResults, enabling attackers to retrieve password hashes. The patch can be manually applied to the wiki page XWiki.LiveTableResultsMacros.

Vendor
xwiki
Product
xwiki-platform
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-10
Original CVE updated
2026-09-18
Advisory published
2026-08-10
Advisory updated
2026-09-18

Who should care

Defenders responsible for XWiki Platform deployments, particularly those using versions 6.2.1 to 18.0.0RC1, 17.10.13, 17.4.9, and 16.10.17, should assess exposure and apply patches or workarounds.

Why it matters

CVE-2026-48048 is a high-severity vulnerability in XWiki Platform that allows password hash retrieval. Defenders should prioritize verifying exposure and applying patches or workarounds.

  • Password hash retrieval can lead to potential credential compromise
  • Defenders must verify exposure and apply patches or workarounds
  • Monitoring for potential password hash retrieval attempts is necessary

Technical summary

The XWiki Platform is vulnerable to password hash retrieval due to an insufficient patch for GHSA-5cf8-vrr8-8hjm. Attackers can retrieve password hashes one bit at a time with 768 requests, impacting versions 6.2.1 to 18.0.0RC1, 17.10.13, 17.4.9, and 16.10.17. The vulnerability affects XWiki Platform's LiveTableResults, enabling attackers to retrieve password hashes. Defenders should prioritize verifying exposure and applying patches or workarounds for affected versions. The patch can be manually applied to the wiki page XWiki.LiveTableResultsMacros.

Defensive priority

Defenders should prioritize verifying exposure and applying patches for XWiki Platform versions 6.2.1 to 18.0.0RC1, 17.10.13, 17.4.9, and 16.10.17.

Recommended defensive actions

  • Verify XWiki Platform version and check for exposure
  • Apply patches or workarounds for affected versions
  • Monitor for potential password hash retrieval attempts
  • Review compensating controls for exposed systems
  • Check relevant monitoring, detection, and logs for exposed assets
  • Track exceptions and retest remediated assets
  • Confirm whether affected product deployments exist in managed environments

Evidence notes

The CVE record and NVD entry provide details on the vulnerability in XWiki Platform, including affected versions and patch information. Evidence limits are based on source-provided information, and defenders should verify exposure and apply patches or workarounds. The vulnerability allows password hash retrieval, impacting XWiki Platform versions 6.2.1 to 18.0.0RC1, 17.10.13, 17.4.9, and 16.10.17.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-48048 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-48048

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-48048 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-48048

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.