CVE-2026-33229 Details
Description
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.4.8 and 17.10.1, an improperly protected scripting API allows any user with script right to bypass the sandboxing of the Velocity scripting API and execute, e.g., arbitrary Python scripts, allowing full access to the XWiki instance and thereby compromising the confidentiality, integrity and availability of the whole instance. Note that script right already constitutes a high level of access that we don't recommend giving to untrusted users. This vulnerability is fixed in 17.4.8 and 17.10.1.
A remote code execution vulnerability has been identified in XWiki Platform versions 17.0.0-rc-1 prior to 17.4.8 and 17.5.0-rc-1 prior to 17.10.1. The issue arises from an improperly protected scripting API that allows users with script rights to bypass the sandboxing of the Velocity scripting API. This vulnerability enables the execution of arbitrary Python scripts, granting full access to the XWiki instance and compromising the confidentiality, integrity, and availability of the entire instance. It is important to note that script rights already represent a high level of access, which should not be granted to untrusted users.
Users can upgrade to XWiki Platform versions 17.4.8 or 17.10.1, where this vulnerability has been patched by requiring programming rights to access the affected scripting API.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/xwiki/xwiki-platform/commit/9fe84da66184c05953df9466cf3a4acd15a46e63 | [email protected] | Patch |
| https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-h259-74h5-4rh9 | [email protected] | PatchVendor Advisory |
| https://jira.xwiki.org/browse/XWIKI-23698 | [email protected] | ExploitVendor Advisory |
| https://jira.xwiki.org/browse/XWIKI-23702 | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| xwiki xwiki | >= 17.0.0, < 17.4.8 >= 17.5.0, < 17.10.1 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 14, 2026 | Initial Analysis | [email protected] |
| Apr 10, 2026 | CVE Modified | CISA-ADP |
| Apr 8, 2026 | New CVE Received | [email protected] |