Improper Authorization in XWiki platform - CVE-2025-49585
Published: May 5, 2026
XWiki platform
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary code with the rights of another user.
The vulnerability exists due to improper access control in XClass definitions when a document containing dangerous XClass properties is later edited by a higher-privileged user. A remote user can create a malicious XClass definition to execute arbitrary code with the rights of another user.
User interaction is required because a user with script, admin, or programming right must later edit the same document.