Improper access control in XWiki platform - CVE-2021-32620
Published: May 18, 2021 / Updated: May 5, 2026
XWiki platform
XWiki
Description
The vulnerability allows a remote user to reactivate a disabled account.
The vulnerability exists due to improper access control in the account activation mechanism when using the registration activation link after the account has been disabled. A remote user can use a previously issued activation link to reactivate a disabled account.
Only users registered with email verification are affected.