Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-53966— XWiki Platform: Privilege escalation from edit to script right through Live Data editing

Quick assessment

Affected
xwiki xwiki-platform
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

XWiki Platform 是一个通用的 Wiki 平台。从 13.4-rc-1 到 16.10.17、17.4.10、17.10.4 和 18.1.0-rc-1 版本中,Live Data 编辑 REST API 允许能够编辑某个页面的用户在不执行正常的文档保存授权检查的情况下修改该页面的权限设置。用户因此可以授予脚本权限,并随后执行可能存在风险的 Velocity 脚本,或向客户端发送未经过滤的 HTML 和 JavaScript 代码。同样的检查缺失还可能绕过以 及相关用户文档事件监听器形式实现的扩展安全控

CVSS 7.1 · High EPSS 0.04% · P12

Possible ATT&CK Techniques 1 AI

T1210 · Exploitation of Remote Services
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-53966

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
XWiki Platform: Privilege escalation from edit to script right through Live Data editing
Source: CVE Program / CVE List V5
Vulnerability Description
XWiki Platform is a generic wiki platform. From 13.4-rc-1 until 16.10.17, 17.4.10, 17.10.4, and 18.1.0-rc-1, the Live Data edit REST API allows a user who can edit a page to change that page's rights without executing the normal document-saving authorization checks. The user can grant script right and then execute potentially dangerous Velocity scripts or send unfiltered HTML and JavaScript to clients. The same missing checks can circumvent extension security controls implemented as listeners for UserUpdatingDocumentEvent and related user document events. This issue is fixed in versions 16.10.17, 17.4.10, 17.10.4, and 18.1.0-rc-1.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
xwiki xwiki-platform >= 13.4-rc-1, < 16.10.17 -

II. Public POCs for CVE-2026-53966

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-53966

登录查看更多情报信息。

Patches & Fixes for CVE-2026-53966 (4)

Vendor Advisories for CVE-2026-53966 (1)

Vendor Pages for CVE-2026-53966 (4)

Other References for CVE-2026-53966 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-53966

No comments yet


Leave a comment