PT-2026-43466 · Xwiki · Xwiki

Published

2026-05-21

·

Updated

2026-05-26

·

CVE-2026-48048

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions XWiki versions prior to 18.0.0RC1 XWiki versions prior to 17.10.13 XWiki versions prior to 17.4.9 XWiki versions prior to 16.10.17
Description An insufficient patch allows for the discovery of password hashes one bit at a time by using modified parameters in LiveTableResults. By sending 768 requests, an attacker can retrieve the full password salt and hash of a user.
Recommendations Update to version 18.0.0RC1. Update to version 17.10.13. Update to version 17.4.9. Update to version 16.10.17. As a temporary workaround, manually apply the patch to the XWiki.LiveTableResultsMacros wiki page.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-48048
GHSA-RH28-MQJ4-8X59

Affected Products

Xwiki