Incorrect authorization in XWiki platform - CVE-2025-49582
Published: May 5, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper access control in required rights analyzers for macros when analyzing macro parameters that contain XWiki syntax. A remote user can add malicious script macros hidden in non-lowercase or otherwise unanalyzed parameters to execute arbitrary code.
User interaction is required when another user with programming rights edits the page.