{"id":"CVE-2025-29926","aliases":["GHSA-gfp2-6qhm-7x43"],"url":"https://o3.security/vulnerability/CVE-2025-29926","summary":"The WikiManager REST API allows any user to create wikis","details":"### Impact\n\nAny user can exploit the WikiManager REST API to create a new wiki, where the user could become an administrator and so performs other attacks on the farm.\nNote that this REST API is not bundled in XWiki Standard by default: it needs to be installed manually through the extension manager.\n\n### Patches\n\nThe problem has been patched in versions 15.10.15, 16.4.6 and 16.10.0 of the REST module.\n\n### Workarounds\n\nThere's no workaround other than upgrading the dependency.\n\n### References\n\n * JIRA ticket: https://jira.xwiki.org/browse/XWIKI-22490\n * Commit of the fix: https://github.com/xwiki/xwiki-platform/commit/82aa670106c7f5e6238ca6ed59a52d1800e05b99\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n* Open an issue in [Jira XWiki.org](https://jira.xwiki.org/)\n* Email us at [Security Mailing List](mailto:security@xwiki.org)\n\n### Attribution\n\nYou can specify here who reported the issue.","published":"2025-03-19T17:40:44.937Z","modified":"2026-08-12T15:16:22.270213Z","cvss":null,"epss":{"score":0.00555,"percentile":0.44899,"asOf":"2026-09-16"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.xwiki.platform:xwiki-platform-wiki-rest-default","fixedVersion":"15.10.15"},{"ecosystem":"Maven","name":"org.xwiki.platform:xwiki-platform-wiki-rest-default","fixedVersion":"16.4.6"},{"ecosystem":"Maven","name":"org.xwiki.platform:xwiki-platform-wiki-rest-default","fixedVersion":"16.10.0"}],"fix":{"url":"https://github.com/xwiki/xwiki-platform/commit/82aa670106c7f5e6238ca6ed59a52d1800e05b99","label":"xwiki/xwiki-platform@82aa670"},"references":[{"type":"WEB","url":"https://jira.xwiki.org/browse/XWIKI-22490"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/29xxx/CVE-2025-29926.json"},{"type":"ADVISORY","url":"https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-gfp2-6qhm-7x43"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-29926"},{"type":"FIX","url":"https://github.com/xwiki/xwiki-platform/commit/82aa670106c7f5e6238ca6ed59a52d1800e05b99"},{"type":"PACKAGE","url":"https://github.com/xwiki/xwiki-platform"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T15:16:22.270213Z"}}