Protection Mechanism Failure in XWiki platform - CVE-2021-32729
Published: July 1, 2021 / Updated: May 5, 2026
XWiki platform
XWiki
Description
The vulnerability allows a remote user to modify authentication failure records.
The vulnerability exists due to protection mechanism failure in the authentication script service method when handling requests to reset authentication failures. A remote privileged user can invoke the reset method to modify authentication failure records.
User interaction is required.