Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
☕ Maven
Not in CISA KEV

XWiki Platform has an Unauthenticated XAR Import via REST /wikis/{wikiName}GHSA-qrvh-r3f2-9h4r

Fix: xwiki/xwiki-platform@4b7b95b

GHSA-qrvh-r3f2-9h4r is a CWE-862 vulnerability in org.xwiki.platform:xwiki-platform-rest-server. A fix is available for org.xwiki.platform:xwiki-platform-rest-server — see the affected versions and patch details below.

Also known asCVE-2026-33137
Published
Updated
Affected
4 pkgs
Patched
4 / 4
Exploits
None indexed
Exploitation data as of Oct 7, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

Exploitation Status

No confirmed exploitation observed yet

  • CISA assesses this as automatable — exploitation doesn’t require manual, per-target effort, which raises the odds of mass scanning and opportunistic attacks.
  • A successful exploit gives an attacker total control of the affected component, not partial access.
  • CISA’s own triage has not observed active exploitation or public proof-of-concept code for this CVE as of its last assessment.

Exploitation and automatability from CISA’s SSVC triage for GHSA-qrvh-r3f2-9h4r.

EPSS Exploitation Probability

via FIRST.org ↗
0.9%probability of exploitation in next 30 days
Lower Risk0.00%
Lower risk than most CVEs58th percentile — riskier than 58% of all scored CVEsHighest risk
0.00%0.46%0.92%1.38%0.0%0.9%Jun 26Sep 26Oct 26

Probability of exploitation in the next 30 days, from FIRST.org EPSS.

Real-World Exposure

4 pkgs affected
☕org.xwiki.platform:xwiki-platform-rest-server☕org.xwiki.platform:xwiki-platform-rest-server☕org.xwiki.platform:xwiki-platform-rest-server☕org.xwiki.platform:xwiki-platform-rest-server

Real-time download stats are indexed for npm and PyPI packages. This vulnerability affects Maven packages — download data is not available via public APIs for these ecosystems.

Description

Impact

POST /wikis/{wikiName} executes a XAR import without performing any authentication or authorization checks, allowing an unauthenticated attacker to create or update documents in the target wiki

Patches

This vulnerability has been patched in XWiki 16.10.17, 17.4.9, 17.10.3, 18.0.1 and 18.1.0-rc-1.

Workarounds

XWiki is not aware of any workarounds other than adding a rule into an HTTP proxy to prevent access POST request in the /wikis/{wikiName}[/] endpoint.

Resources

For more information

If there are any questions or comments about this advisory:

Attribution

Reported by Sho Odagiri (GMO Cybersecurity by Ierae, Inc.).

Affected Packages

4 total 4 fixed
EcosystemPackageVulnerable rangeFix
☕Mavenorg.xwiki.platform:xwiki-platform-rest-server≥ 15.10.6&&< 16.10.1716.10.17org.xwiki.platform:xwiki-platform-rest-server:16.10.17
☕Mavenorg.xwiki.platform:xwiki-platform-rest-server≥ 17.0.0-rc-1&&< 17.4.917.4.9org.xwiki.platform:xwiki-platform-rest-server:17.4.9
☕Mavenorg.xwiki.platform:xwiki-platform-rest-server≥ 17.5.0&&< 17.10.317.10.3org.xwiki.platform:xwiki-platform-rest-server:17.10.3
☕Mavenorg.xwiki.platform:xwiki-platform-rest-server≥ 18.0.0-rc-1&&< 18.1.0-rc-118.1.0-rc-1org.xwiki.platform:xwiki-platform-rest-server:18.1.0-rc-1

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for org.xwiki.platform:xwiki-platform-rest-server, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.

  2. Fix

    Update org.xwiki.platform:xwiki-platform-rest-server to 16.10.17 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-qrvh-r3f2-9h4r is resolved across your whole dependency graph.

  3. Workarounds

    Put an independent control in front of the weakness: restrict the affected endpoint or interface to trusted networks, require an additional authentication factor or proxy-level check, and invalidate existing sessions and credentials in case the flaw has already been used.

Frequently Asked Questions

### Impact `POST /wikis/{wikiName}` executes a XAR import without performing any authentication or authorization checks, allowing an unauthenticated attacker to create or update documents in the target wiki ### Patches This vulnerability has been patched in XWiki 16.10.17, 17.4.9, 17.10.3, 18.0.1 and 18.1.0-rc-1. ### Workarounds XWiki is not aware of any workarounds other than adding a rule into an HTTP proxy to prevent access POST request in the `/wikis/{wikiName}[/]` endpoint. ### Resources * https://jira.xwiki.org/browse/XWIKI-23953 * https://github.com/xwiki/xwiki-platform/commit/4b
O3 Security · Impact-Aware SCA

Is GHSA-qrvh-r3f2-9h4r in your dependencies?

Find it across Maven, including transitive dependencies.

XWiki Platform has an Unauthenticated XAR Import via…