Improper access control in XWiki platform - CVE-2023-29513
Published: April 18, 2023 / Updated: May 5, 2026
XWiki platform
XWiki
Description
The vulnerability allows a remote user to create a new user account even when registration is disabled.
The vulnerability exists due to improper access control in the distribution/firstadminuser.wiki template macro when rendering the template in the wrong context. A remote user can invoke the template through a crafted request to create a new user account even when registration is disabled.
Exploitation requires guest view rights on at least one document, and on installations starting with XWiki 14.5 a valid CSRF token is also required.