{"id":"CVE-2026-26000","aliases":["GHSA-74rh-c5rh-88vg"],"url":"https://o3.security/vulnerability/CVE-2026-26000","summary":"XWiki Platform affected by click-jacking through CSS injection in comments","details":"### Impact\n\nIt's possible using comments to inject CSS that would transform the full wiki in a link area leading to a malicious page. All versions of XWiki are impacted by this kind of attack. \n\n### Patches\n\nThe problem has been patched not by preventing injecting CSS in comments, which is currently a feature of XWiki, but by requiring confirmation from users when driving them to untrusted domains after clicking on a link, thus preventing any click-jacking attack. \nThis security measure has been put in place in XWiki 17.9.0, 17.4.6, 16.10.13.\n\n### Workarounds\n\nThere's no out-of-the-box workaround, but it should be possible to partly reuse [the javascript code provided for the security measure](https://github.com/xwiki/xwiki-platform/blob/xwiki-platform-17.9.0/xwiki-platform-core/xwiki-platform-web/xwiki-platform-web-war/src/main/webapp/resources/uicomponents/link/link-protection.js) in a JSX object inside the wiki, to request the same kind of confirmation. \n\n### References\n  * JIRA ticket: https://jira.xwiki.org/browse/XWIKI-23433\n  * Documentation of the new security measure: https://www.xwiki.org/xwiki/bin/view/ReleaseNotes/Data/XWiki/17.9.0RC1/Entry006/\n  * Commit for the security fix: https://github.com/xwiki/xwiki-platform/commit/29cb81f3a5387cf822d7e7534bdd63903275f86b\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n* Open an issue in [Jira XWiki.org](https://jira.xwiki.org/)\n* Email us at [Security Mailing List](mailto:security@xwiki.org)\n\n### Attribution\n\nThanks Tomas Keech (Sentrium Security Ltd) for reporting this vulnerability.","published":"2026-02-12T20:30:07.263Z","modified":"2026-08-12T03:51:16.299691245Z","cvss":null,"epss":{"score":0.00284,"percentile":0.20986,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.xwiki.platform:xwiki-platform-web","fixedVersion":"17.9.0"},{"ecosystem":"Maven","name":"org.xwiki.platform:xwiki-platform-web","fixedVersion":"17.4.6"},{"ecosystem":"Maven","name":"org.xwiki.platform:xwiki-platform-web","fixedVersion":"16.10.13"}],"fix":{"url":"https://github.com/xwiki/xwiki-platform/pull/4645","label":"xwiki/xwiki-platform#4645"},"references":[{"type":"WEB","url":"https://github.com/xwiki/xwiki-platform/releases/tag/xwiki-platform-17.4.6"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/26xxx/CVE-2026-26000.json"},{"type":"ADVISORY","url":"https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-74rh-c5rh-88vg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-26000"},{"type":"WEB","url":"https://github.com/xwiki/xwiki-platform/pull/4645"},{"type":"WEB","url":"https://github.com/xwiki/xwiki-platform/commit/29cb81f3a5387cf822d7e7534bdd63903275f86b"},{"type":"WEB","url":"https://github.com/xwiki/xwiki-platform/commit/7b5a4f8c34d9b1da3d966e17f7dbccabac448e75"},{"type":"PACKAGE","url":"https://github.com/xwiki/xwiki-platform"},{"type":"WEB","url":"https://jira.xwiki.org/browse/XWIKI-23433"},{"type":"WEB","url":"https://www.xwiki.org/xwiki/bin/view/ReleaseNotes/Data/XWiki/17.9.0RC1/Entry006"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:16.299691245Z"}}