Improper Authorization in XWiki platform - CVE-2025-49583
Published: May 5, 2026
XWiki platform
Detailed vulnerability description
The vulnerability allows a remote user to send spam or phishing notifications to other users.
The vulnerability exists due to improper access control in NotificationEmailRendererClass email templates when an administrator edits and saves a document previously created by a low-privileged user with an XWiki.Notifications.Code.NotificationEmailRendererClass object. A remote user can create such a document to send spam or phishing notifications to other users.
User interaction is required because an administrator must edit and save the crafted document.