Improper Authorization in XWiki platform - CVE-2022-36090

 

Improper Authorization in XWiki platform - CVE-2022-36090

Published: September 8, 2022 / Updated: May 5, 2026


Vulnerability identifier: #VU130019
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-36090
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information and modify data.

The vulnerability exists due to improper authorization in resource handlers, including the REST service, when handling requests from inactive users. A remote user can send a crafted REST call or access unprotected extension resource handlers to disclose sensitive information and modify data.

The issue affects inactive users, including not yet activated and disabled accounts.


Affected software

XWiki platform

How to mitigate CVE-2022-36090

Install security update from vendor's website.

XWiki platform - addressed in versions 13.10.5, 14.3 rc-1

External References

Related Security Bulletins