PT-2025-40900 · Xwiki · Xwiki

Thomas Mortagne

·

Published

2025-10-06

·

Updated

2025-10-23

·

CVE-2025-49594

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions XWiki versions 2.17.1 through 2.18.1
Description XWiki OpenID Connect (OIDC) contains tools for manipulating the OpenID Connect protocol. Individuals with VIEW access to a user profile can generate a token for that user in versions prior to 2.18.2. If the XWiki instance permits token authentication, this allows authentication as any user, as user profiles are often viewable by other registered users.
Recommendations Upgrade to version 2.18.2. Disable token access.

Exploit

Fix

Improper Authorization

Weakness Enumeration

Related Identifiers

BDU:2025-14640
CVE-2025-49594
GHSA-F2HF-PFRJ-VRM7

Affected Products

Xwiki