CVE-2026-48047 Details
Description
XWiki Platform WebJars API is a package for XWiki, a generic wiki platform. Starting with version 9.6-rc-1 and prior to versions 16.10.17, 17.4.9, and 17.10.3, a potential path traversal vulnerability allow an attacker who manages to get a malicious WebJar extension installed on the wiki to write arbitrary files. While the consequences could be severe like overriding configuration files and setting the superadmin password, the attack first requires that the attacker already has admin access to at least a subwiki to be able to install a malicious extension. Further, the attacker needs to publish a malicious extension in an extension repository that is configured in the instance. This vulnerability has been patched in XWiki 16.10.17, 17.4.9, 17.10.3, and 18.0.0RC1. XWiki is not aware of any workarounds except for being careful whom developers grant script and admin rights to.
A path traversal vulnerability has been identified in the XWiki Platform WebJars API, affecting versions 9.6-rc-1 prior to 16.10.17, 17.4.9, and 17.10.3. This vulnerability allows an attacker with admin access to a subwiki to exploit a malicious WebJar extension, potentially overwriting critical configuration files or altering the superadmin password. The issue arises from inadequate validation of resource paths in WebJar extensions, enabling the manipulation of file write locations.
Users can update to XWiki versions 16.10.17, 17.4.9, 17.10.3, or 18.0.0RC1 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 7, 2026CISA-ADP
Assessed Aug 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://jira.xwiki.org/browse/XWIKI-23902 | CISA-ADP | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/xwiki/xwiki-platform/commit/9f747fcd3200259a1de51957d3f5f6acc8e3816c | [email protected] | Source CodeVendor |
| https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-vgwr-23fq-pr7g | [email protected] | AdvisoryRemedyVendor |
| https://jira.xwiki.org/browse/XWIKI-23902 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-24 | Path Traversal: '../filedir' | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| XWiki | >= 9.6-rc-1, < 16.10.17 >= 17.0.0-rc-1, < 17.4.9 (semver) >= 17.5.0-rc-1, < 17.10.3 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 10, 2026 | CVE Modified | CISA-ADP |
| Aug 7, 2026 | New CVE Received | [email protected] |
Volerion