Improper privilege management in XWiki platform - CVE-2022-31166
Published: September 7, 2022 / Updated: May 5, 2026
XWiki platform
XWiki
Description
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper privilege management in XWikiRights resolution of groups when editing a right with the object editor. A remote user can add a supplementary empty group value that is resolved as a reference to XWiki.WebHome and then add an XWikiGroup object to grant themselves the privileges related to the edited right to escalate privileges.
The issue depends on XWiki.WebHome being editable, since an empty group value is resolved as a reference to that page.