XWiki Platform, Privilege Escalation, CVE-2026-53966 (High) -DC-Aug2026-1677

Listen to this Post

XWiki Platform is a generic wiki platform offering collaborative features and extensibility through various macros and APIs. One of its core features is the Live Data and Live Table functionality, which allows users to interact with and display data dynamically.
CVE-2026-53966 is a privilege escalation vulnerability present in the XWiki Platform’s Live Data Live Table Connector. The core of the issue lies in the Live Data edit REST API. An authenticated user with only edit rights on a page can exploit this API to modify the rights of that same page.
By manipulating the request to the REST API, the user can grant themselves the `script` right on the page. The `script` right is a powerful permission in XWiki, as it allows the execution of Velocity scripts. Velocity is a Java-based template engine that can be used to execute arbitrary Java code, posing a significant security risk. Furthermore, this right allows the user to send unfiltered HTML and JavaScript to the client, leading to potential Cross-Site Scripting (XSS) attacks.
The vulnerability also has broader implications. It can be used to circumvent other security checks that might be implemented as event listeners for `UserUpdatingDocumentEvent` and similar user-related events. This means that even if an extension has additional security measures, they could be bypassed through this flaw.
The vulnerability affects a wide range of XWiki versions. The affected versions include all releases from 13.4-rc-1 up to, but not including, 16.10.17, as well as versions 17.0.0-rc-1 to 17.4.10, 17.5.0-rc-1 to 17.10.4, and 18.0.0-rc-1 to 18.1.0-rc-1. This broad impact necessitates immediate attention from administrators.

DailyCVE Form

Platform: XWiki Platform
Version: 13.4-rc-1 to <16.10.17, 17.0.0-rc-1 to <17.4.10, 17.5.0-rc-1 to <17.10.4, 18.0.0-rc-1 to <18.1.0-rc-1
Vulnerability: Privilege Escalation
Severity: High
Date: Aug 19, 2026

Prediction: Already Patched (Apr 9, 2026)

What Undercode Say

Analytics and detection can be performed by auditing logs and checking for unexpected API calls.

Check for suspicious POST requests to the Live Data edit REST API
grep "POST /rest/livedata" /var/log/xwiki/access.log
Search for specific user rights changes in logs
grep "rights" /var/log/xwiki/xwiki.log | grep "script"
Audit current user rights on critical pages
curl -u admin:password "http://xwiki.domain.com/xwiki/rest/wikis/xwiki/spaces/Main/pages/WebHome/rights"

Exploit: (Educational Purposes!)

A proof-of-concept for this vulnerability would involve an authenticated user sending a crafted PUT or POST request to the Live Data edit REST API endpoint, modifying the `rights` object for a page to include `script` permissions. The exact request structure would target the page’s ACL (Access Control List).

Example exploit request (Conceptual)
curl -X PUT "http://xwiki.domain.com/xwiki/rest/wikis/xwiki/spaces/Main/pages/WebHome/rights" \
-H "Content-Type: application/json" \
-d '{"users": [{"name": "attacker", "rights": ["edit", "script"]}]}'

Protection

Protection from this CVE is straightforward and requires upgrading to a patched version. The vulnerability has been fixed in XWiki versions 16.10.17, 17.4.10, 17.10.4, and 18.1.0. Administrators are strongly advised to upgrade to one of these versions immediately. No other workarounds are currently known.

Impact

The impact of this vulnerability is severe. Any user with edit permissions can escalate their privileges to script rights. This allows for:
– Remote Code Execution (RCE): Through the execution of malicious Velocity scripts, an attacker can gain full control over the XWiki instance and potentially the underlying server.
– Data Breach: Unauthorized access to sensitive data stored within the wiki.
– Cross-Site Scripting (XSS): The ability to inject malicious JavaScript, leading to session hijacking, defacement, and phishing attacks.
– Bypass of Security Controls: Circumvention of other security measures implemented as event listeners, rendering them ineffective.
Given the ease of exploitation and the high potential for damage, this vulnerability should be considered a critical risk for any deployment running an affected version.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top