Junglewise Threat Intelligence

CVE-2026-34151: XWiki Platform is a generic wiki platform. Prior to 17.10.5 and 18.2.0, the /skin/ action in com.xpn.xwiki.web.SkinAction can resolve double

CVE-2026-34151 · Severity: high · CVSS 4 · Published 2026-09-14

Vendors: Xwiki.

Executive brief

XWiki is an open-source enterprise wiki platform. A security vulnerability in how it handles certain web requests when running on Jetty 12+ allows unauthorized users to access sensitive files on the server. This could lead to the exposure of system passwords or internal configuration files, potentially compromising the entire server or the application's data.

Technical details

A path traversal vulnerability exists in XWiki Platform's 'Old Core' component when deployed on Jetty 12 or newer. The vulnerability is located in the '/skin/' action endpoint, where insufficient validation of the resource path allows an attacker to use double-encoded traversal sequences (e.g., '..%252f') to escape the intended directory. This can be exploited by a remote, unauthenticated attacker via a specially crafted URL to read any file the Jetty process has permissions to access, including sensitive system files like '/etc/passwd' or XWiki configuration files like 'xwiki.cfg'. The issue is patched in versions 17.10.5 and 18.2.0; users on older versions can mitigate the risk by using Tomcat or Jetty versions prior to 12.

Affected products

  • XWiki XWiki Platform Old Core < 17.10.5, >= 18.0.0-rc-1, < 18.2.0

Timeline

  • 2026-07-06: disclosed
  • 2026-07-07: advisory

References