CVE-2026-23734Disclosure

LOWCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

XWiki Platform is a generic wiki platform. Versions prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17 allow access to read configuration files by using URLs such as http://localhost:8080/bin/ssx/Main/WebHome?resource=/../../WEB-INF/xwiki.cfg&minify=false, leading to Path Traversal. The vulnerability is can be exploited via resources parameter the ssx and jsx endpoints by using leading slashes. This issue has been patched in 18.1.0-rc-1, 17.10.3, 17.4.9, 16.10.17.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-23

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-05-22); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-22: 1Mentions · 2026-05-26: 1PoC Mentioned / Linked · 2026-05-22: 1Patch / Workaround · 2026-05-26: 1Technical Details · 2026-05-22: 1Technical Details · 2026-05-26: 105-2205-26
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Classification over time
DateTotalLabels
2026-05-221
Disclosure1
2026-05-261
Patch1
Full discourse2 posts
  • Horizon3.ai@Horizon3ai
    Disclosure

    🚨 An internal wiki shouldn’t become an unauthenticated file browser. But that’s exactly what CVE-2026-23734 enables in XWiki. Rapid Response test now available. https://t.co/fqWejV8iEd

    Post summary

    The tweet announces that CVE-2026-23734 turns an internal XWiki into an unauthenticated file browser and notes a Rapid Response test is available for validation.

    13020267
    2.8K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 Critical - XWiki Platform Path Traversal → Config File Read (CVE-2026-23734) An unauthenticated attacker can read arbitrary server-side files, including WEB-INF/xwiki.cfg, by passing a leading-slash traversal sequence via the resource parameter on the /bin/ssx/ and /bin/jsx/ endpoints. No authentication, no user interaction, and no special configuration required. Confirmed exploitable on Tomcat deployments (CVSS 9.3). 👉 Affected: org.xwiki.commons:xwiki-commons-classloader-api ≥ 4.2-milestone-2 < 16.10.17, ≥ 17.0.0-rc-1 < 17.4.9, ≥ 17.5.0 < 17.10.3, ≥ 18.0.0-rc-1 < 18.1.0-rc-1 | Upgrade to 16.10.17 / 17.4.9 / 17.10.3 / 18.1.0-rc-1

    Post summary

    The advisory reports a critical path traversal vulnerability in XWiki (CVE‑2026‑23734) that allows unauthenticated file reads, listing affected versions and urging users to upgrade to the patched releases.

    0000083
    196 followersView on X

Explore more