Improper Authorization in XWiki platform - CVE-2025-49583

 

Improper Authorization in XWiki platform - CVE-2025-49583

Published: May 5, 2026


Vulnerability identifier: #VU129883
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2025-49583
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: XWiki
Affected software:
XWiki platform

Detailed vulnerability description

The vulnerability allows a remote user to send spam or phishing notifications to other users.

The vulnerability exists due to improper access control in NotificationEmailRendererClass email templates when an administrator edits and saves a document previously created by a low-privileged user with an XWiki.Notifications.Code.NotificationEmailRendererClass object. A remote user can create such a document to send spam or phishing notifications to other users.

User interaction is required because an administrator must edit and save the crafted document.


How to mitigate CVE-2025-49583

Install security update from vendor's website.

Sources