Junglewise Threat Intelligence

CVE-2026-40104: XWiki's REST APIs can list all pages/spaces, leading to unavailability

CVE-2026-40104 · Severity: high · CVSS 8.2 · Published 2026-04-14

Executive brief

### Impact REST API endpoints like `/xwiki/rest/wikis/xwiki/spaces/AnnotationCode/pages/AnnotationConfig/objects/AnnotationCode.AnnotationConfig/0/properties` list all available pages as part of the metadata for database list properties, which can exhaust available resources on large wikis.

### Patches This problem has been patched by applying the configured query limit also to the available values for database list properties in XWiki 16.10.16, 17.4.8 and 17.10.1.

### Workarounds We're not aware of any workarounds apart from upgrading the affected modules.

References