CVE-2026-33137Disclosure

MEDIUMCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform is a generic wiki platform. In versions starting with 15.10.6 and prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17, the POST /wikis/{wikiName} API executes a XAR import without performing any authentication or authorization checks, allowing an unauthenticated attacker to create or update documents in the target wiki. This vulnerability has been patched in XWiki 16.10.17, 17.4.9, 17.10.3, 18.0.1 and 18.1.0-rc-1.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-05-21); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-21: 1Mentions · 2026-05-26: 1PoC Mentioned / Linked · 2026-05-26: 1Exploit Tool / Code · 2026-05-26: 1Patch / Workaround · 2026-05-26: 1Technical Details · 2026-05-21: 1Technical Details · 2026-05-26: 105-2105-26
Signal classification2 categories
Disclosure
150.0%
PoC
150.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-211
Disclosure1
2026-05-261
PoC1
Full discourse2 posts
  • dbugs@ptdbugs
    PoC

    🔔 A PoC/exploit has been discovered for vulnerability CVE-2026-33137 PT ID: PT-2026-42223 Vendor: xwiki Product: xwiki-platform Description: XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform is a generic wiki platform. In versions prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17, the POST /wikis/{wikiName} API executes a XAR import without performing any authentication or authorization checks, allowing an unauthenticated attacker to create or update documents in the target wiki. This vulnerability has been patched in XWiki 16.10.17, 17.4.9, 17.10.3, 18.0.1 and 18.1.0-rc-1. References: • https://dbugs.ptsecurity.com/vulnerability/PT-2026-42223 Link: https://github.com/portbuster1337/CVE-2026-33137 #dbugs_vuln

    Post summary

    A proof‑of‑concept exploit for CVE‑2026‑33137, allowing unauthenticated XAR imports in XWiki platforms, has been published with a GitHub link, and the weakness has already been patched in recent releases.

    00011387
    1.2K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    🚨🚨🚨 『allowing an unauthenticated attacker to create or update documents in the target wiki』 『Reported by Sho Odagiri (GMO Cybersecurity by Ierae, Inc.).』 CVE-2026-33137 Unauthenticated XAR Import via REST /wikis/{wikiName} · Advisory · xwiki https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-qrvh-r3f2-9h4r

    Post summary

    The tweet alerts that CVE-2026-33137 permits unauthenticated users to create or update wiki documents via a REST endpoint; it provides a concise description but no PoC, exploit, or patch details.

    00011399
    6.9K followersView on X

Explore more