CVE-2026-26000 Details
Description
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.9.0, 17.4.6, and 16.10.13, it's possible using comments to inject CSS that would transform the full wiki in a link area leading to a malicious page. This vulnerability is fixed in 17.9.0, 17.4.6, and 16.10.13.
A clickjacking vulnerability has been identified in XWiki Platform versions prior to 17.9.0, 17.4.6, and 16.10.13. This issue allows users to inject CSS through comments, which can then be used to manipulate the appearance of the wiki, creating a deceptive link area that directs to a malicious page. All XWiki versions are susceptible to this type of attack.
Users can update to XWiki Platform versions 17.9.0, 17.4.6, or 16.10.13 to address this vulnerability. For those unable to update, it may be possible to implement a partial workaround using the JavaScript code available in the XWiki 17.9.0 release, which can be reused in a JSX object within the wiki to request confirmation before clicking on links to untrusted domains.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/xwiki/xwiki-platform/releases/tag/xwiki-platform-17.4.6 | [email protected] | ProductRelease Notes |
| https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-74rh-c5rh-88vg | [email protected] | PatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1021 | Improper Restriction of Rendered UI Layers or Frames | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| xwiki xwiki | < 16.10.13 >= 17.0.0, < 17.4.6 >= 17.5.0, < 17.9.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 19, 2026 | Initial Analysis | [email protected] |
| Feb 12, 2026 | New CVE Received | [email protected] |