Improper Authorization in XWiki platform - CVE-2025-49583

 

Improper Authorization in XWiki platform - CVE-2025-49583

Published: May 5, 2026


Vulnerability identifier: #VU129883
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-49583
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to send spam or phishing notifications to other users.

The vulnerability exists due to improper access control in NotificationEmailRendererClass email templates when an administrator edits and saves a document previously created by a low-privileged user with an XWiki.Notifications.Code.NotificationEmailRendererClass object. A remote user can create such a document to send spam or phishing notifications to other users.

User interaction is required because an administrator must edit and save the crafted document.


Affected software

XWiki platform

How to mitigate CVE-2025-49583

Install security update from vendor's website.

XWiki platform - addressed in versions 15.10.16, 16.4.7, 16.10.2

External References

Related Security Bulletins