{"id":"CVE-2026-33137","aliases":["GHSA-qrvh-r3f2-9h4r"],"url":"https://o3.security/vulnerability/CVE-2026-33137","summary":"XWiki Platform has an Unauthenticated XAR Import via REST /wikis/{wikiName}","details":"### Impact\n\n`POST /wikis/{wikiName}` executes a XAR import without performing any authentication or authorization checks, allowing an unauthenticated attacker to create or update documents in the target wiki\n\n### Patches\n\nThis vulnerability has been patched in XWiki 16.10.17, 17.4.9, 17.10.3, 18.0.1 and 18.1.0-rc-1.\n\n### Workarounds\n\nXWiki is not aware of any workarounds other than adding a rule into an HTTP proxy to prevent access POST request in the `/wikis/{wikiName}[/]` endpoint.\n\n### Resources\n\n* https://jira.xwiki.org/browse/XWIKI-23953\n* https://github.com/xwiki/xwiki-platform/commit/4b7b95b79256374d487e9ece1dc48f527966990f\n\n### For more information\n\nIf there are any questions or comments about this advisory:\n* Open an issue in [Jira XWiki.org](https://jira.xwiki.org/)\n* Send an email to the [Security Mailing List](mailto:security@xwiki.org)\n\n### Attribution\n\nReported by Sho Odagiri (GMO Cybersecurity by Ierae, Inc.).","published":"2026-05-20T18:59:17.819Z","modified":"2026-08-12T03:51:48.763665551Z","cvss":null,"epss":{"score":0.00594,"percentile":0.45587,"asOf":"2026-08-15"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.xwiki.platform:xwiki-platform-rest-server","fixedVersion":"16.10.17"},{"ecosystem":"Maven","name":"org.xwiki.platform:xwiki-platform-rest-server","fixedVersion":"17.4.9"},{"ecosystem":"Maven","name":"org.xwiki.platform:xwiki-platform-rest-server","fixedVersion":"17.10.3"},{"ecosystem":"Maven","name":"org.xwiki.platform:xwiki-platform-rest-server","fixedVersion":"18.1.0-rc-1"}],"fix":{"url":"https://github.com/xwiki/xwiki-platform/commit/4b7b95b79256374d487e9ece1dc48f527966990f","label":"xwiki/xwiki-platform@4b7b95b"},"references":[{"type":"WEB","url":"https://jira.xwiki.org/browse/XWIKI-23953"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33137.json"},{"type":"ADVISORY","url":"https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-qrvh-r3f2-9h4r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33137"},{"type":"FIX","url":"https://github.com/xwiki/xwiki-platform/commit/4b7b95b79256374d487e9ece1dc48f527966990f"},{"type":"PACKAGE","url":"https://github.com/xwiki/xwiki-platform"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:48.763665551Z"}}