XWiki Platform has an Unauthenticated XAR Import via REST /wikis/{wikiName}
Package
Affected versions
>= 15.10.6, < 16.10.17
>= 17.0.0-rc-1, < 17.4.9
>= 17.5.0, < 17.10.3
>= 18.0.0-rc-1, < 18.1.0-rc-1
Patched versions
16.10.17
17.4.9
17.10.3
18.1.0-rc-1
Description
Published by the National Vulnerability Database
May 20, 2026
Published to the GitHub Advisory Database
May 26, 2026
Reviewed
May 26, 2026
Impact
POST /wikis/{wikiName}executes a XAR import without performing any authentication or authorization checks, allowing an unauthenticated attacker to create or update documents in the target wikiPatches
This vulnerability has been patched in XWiki 16.10.17, 17.4.9, 17.10.3, 18.0.1 and 18.1.0-rc-1.
Workarounds
XWiki is not aware of any workarounds other than adding a rule into an HTTP proxy to prevent access POST request in the
/wikis/{wikiName}[/]endpoint.Resources
For more information
If there are any questions or comments about this advisory:
Attribution
Reported by Sho Odagiri (GMO Cybersecurity by Ierae, Inc.).
References