Exposure of Private Information ('Privacy Violation') in XWiki platform - CVE-2026-48048
Published: May 21, 2026
XWiki platform
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose password salt and hash values.
The vulnerability exists due to exposure of private personal information in the LiveTableResults component when processing slightly modified LiveTableResults parameters. A remote attacker can send crafted requests to retrieve a user's password salt and hash one bit at a time to disclose password salt and hash values.
The password salt and hash can be reconstructed in 768 requests.