{"id":"CVE-2023-26475","aliases":["GHSA-h6f5-8jj5-cxhr"],"url":"https://o3.security/vulnerability/CVE-2023-26475","summary":"XWiki Platform vulnerable to Remote Code Execution in Annotations","details":"### Impact\n\nThe annotation displayer does not execute the content in a restricted context. This allows executing anything with the right of the author of any document by annotating the document.\n\nTo reproduce: add an annotation with the content `{{groovy}}print \"hello\"{{/groovy}}` and click the yellow scare to get a display of the annotation inline.\n\nThe result is \"hello\" but it should be an error suggesting that it's not allowed to use the groovy macro.\n\n### Patches\nThis has been patched in XWiki 13.10.11, 14.4.7 and 14.10.\n\n### Workarounds\nThere is no easy workaround except to upgrade.\n\n### References\nhttps://jira.xwiki.org/browse/XWIKI-20360\n\nhttps://jira.xwiki.org/browse/XWIKI-20384\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [Jira XWiki.org](https://jira.xwiki.org/)\n* Email us at [Security Mailing List](mailto:security@xwiki.org)\n\n### Attribution\n\nThis vulnerability has been reported by René de Sain @renniepak.","published":"2023-03-02T18:07:04.129Z","modified":"2026-08-12T03:51:21.168857874Z","cvss":{"score":9.9,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"},"epss":{"score":0.63587,"percentile":0.9918,"asOf":"2026-08-28"},"cisaKev":null,"exploitsKnown":2,"affectedPackages":[{"ecosystem":"Maven","name":"org.xwiki.platform:xwiki-platform-annotation-ui","fixedVersion":"13.10.11"},{"ecosystem":"Maven","name":"org.xwiki.platform:xwiki-platform-annotation-ui","fixedVersion":"14.4.7"},{"ecosystem":"Maven","name":"org.xwiki.platform:xwiki-platform-annotation-ui","fixedVersion":"14.10"}],"fix":{"url":"https://github.com/xwiki/xwiki-platform/commit/d87d7bfd8db18c20d3264f98c6deefeae93b99f7","label":"xwiki/xwiki-platform@d87d7bf"},"references":[{"type":"WEB","url":"https://jira.xwiki.org/browse/XWIKI-20360"},{"type":"WEB","url":"https://jira.xwiki.org/browse/XWIKI-20384"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/26xxx/CVE-2023-26475.json"},{"type":"ADVISORY","url":"https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-h6f5-8jj5-cxhr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-26475"},{"type":"FIX","url":"https://github.com/xwiki/xwiki-platform/commit/d87d7bfd8db18c20d3264f98c6deefeae93b99f7"},{"type":"PACKAGE","url":"https://github.com/xwiki/xwiki-platform"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:21.168857874Z"}}