Incorrect authorization in XWiki platform - CVE-2025-49582
Published: May 5, 2026
XWiki platform
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper access control in required rights analyzers for macros when analyzing macro parameters that contain XWiki syntax. A remote user can add malicious script macros hidden in non-lowercase or otherwise unanalyzed parameters to execute arbitrary code.
User interaction is required when another user with programming rights edits the page.