Exploit discussion active in current signal (1 latest mentions)
Immediate actions
Patch affected systems immediately
Hunt for exploitation attempts and persistence artifacts
Increase monitoring for publicly documented tradecraft
Recommended action window: High priority (within 72h)
NVD description
XWiki Platform is a generic wiki platform. Versions prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17 allow access to read configuration files by using URLs such as http://localhost:8080/bin/ssx/Main/WebHome?resource=/../../WEB-INF/xwiki.cfg&minify=false, leading to Path Traversal. The vulnerability is can be exploited via resources parameter the ssx and jsx endpoints by using leading slashes. This issue has been patched in 18.1.0-rc-1, 17.10.3, 17.4.9, 16.10.17.
Peaked 1d ago at 1 mentions (2026-05-22); latest day: 1
2 total mentions across 2 days
Deep dive
>Activity timeline2 mentions / 2d
>Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
>Classification over time
Date
Total
Labels
2026-05-22
1
Disclosure1
2026-05-26
1
Patch1
>Full discourse2 posts
Horizon3.ai@Horizon3ai·
Disclosure
🚨 An internal wiki shouldn’t become an unauthenticated file browser.
But that’s exactly what CVE-2026-23734 enables in XWiki.
Rapid Response test now available. https://t.co/fqWejV8iEd
Post summary
The tweet announces that CVE-2026-23734 turns an internal XWiki into an unauthenticated file browser and notes a Rapid Response test is available for validation.
🚨 Critical - XWiki Platform Path Traversal → Config File Read (CVE-2026-23734)
An unauthenticated attacker can read arbitrary server-side files, including WEB-INF/xwiki.cfg, by passing a leading-slash traversal sequence via the resource parameter on the /bin/ssx/ and /bin/jsx/ endpoints. No authentication, no user interaction, and no special configuration required. Confirmed exploitable on Tomcat deployments (CVSS 9.3).
👉 Affected: org.xwiki.commons:xwiki-commons-classloader-api ≥ 4.2-milestone-2 < 16.10.17, ≥ 17.0.0-rc-1 < 17.4.9, ≥ 17.5.0 < 17.10.3, ≥ 18.0.0-rc-1 < 18.1.0-rc-1 | Upgrade to 16.10.17 / 17.4.9 / 17.10.3 / 18.1.0-rc-1
Post summary
The advisory reports a critical path traversal vulnerability in XWiki (CVE‑2026‑23734) that allows unauthenticated file reads, listing affected versions and urging users to upgrade to the patched releases.