CVE-2026-33229Disclosure(xwiki / xwiki)

LOWCVSS 8.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch xwiki xwiki systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.4.8 and 17.10.1, an improperly protected scripting API allows any user with script right to bypass the sandboxing of the Velocity scripting API and execute, e.g., arbitrary Python scripts, allowing full access to the XWiki instance and thereby compromising the confidentiality, integrity and availability of the whole instance. Note that script right already constitutes a high level of access that we don't recommend giving to untrusted users. This vulnerability is fixed in 17.4.8 and 17.10.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • xwiki

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-04-08); latest day: 1
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
xwiki

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-04-08: 4Mentions · 2026-04-11: 1Patch / Workaround · 2026-04-08: 1Technical Details · 2026-04-08: 204-0804-11
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-04-084
Disclosure4
2026-04-111
General1
Full discourse5 posts
  • blueblue@piedpiper1616
    General

    CVE-2026-33229 - Notes - https://youssefazefzaf.com/posts/cve

    Post summary

    The content only references CVE-2026-33229 with a generic notes link, offering no additional details.

    00032510
    5.5K followersView on X
  • dbugs@ptdbugs
    Disclosure

    XWiki Platform affected by remote code execution with script right through unprotected Velocity scripting API CVE: CVE-2026-33229 PT-Identifier: PT-2026-31324 Vendor: Xwiki Product: xwiki-platform CVSS: 8.6 Credits: n/a Description: XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.4.8 and 17.10.1, an improperly protected scripting API allows any user with script right to bypass the sandboxing of the Velocity scripting API and execute, e.g., arbitrary Python scripts, allowing full access to the XWiki instance and thereby compromising the confidentiality, integrity and availability of the whole instance. Note that script right already constitutes a high level of access that we don't recommend giving to untrusted users. This vulnerability is fixed in 17.4.8 and 17.10.1. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-33229 • https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-h259-74h5-4rh9 • https://github.com/xwiki/xwiki-platform/commit/9fe84da66184c05953df9466cf3a4acd15a46e63 • https://jira.xwiki.org/browse/XWIKI-23698 • https://jira.xwiki.org/browse/XWIKI-23702 #dbugs_vuln

    Post summary

    The vulnerability CVE-2026-33229 in XWiki allows arbitrary Python execution for users with script rights; it is patched in newer releases with no reported active exploitation or PoC disclosed.

    00010173
    788 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-33229 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.4.8 and 17.10.1, an improperly protected scriptin… https://www.cve.org/CVERecord?id=CVE-2026-33229 ----- Traducción: CVE-2026-33229 XWi… http://infoflow.cloud`

    Post summary

    The tweet simply announces CVE-2026-33229 with a brief description and version references, serving as a disclosure notice without detailed technical or exploit information.

    0000022
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33229 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.4.8 and 17.10.1, an improperly protected scriptin… https://www.cve.org/CVERecord?id=CVE-2026-33229

    Post summary

    The text announces CVE-2026-33229 against XWiki Platform before versions 17.4.8 and 17.10.1, noting an improperly protected script issue, but provides no PoC, exploit, patch, or further technical detail.

    00000108
    57.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-33229 Arbitrary Code Execution in XWiki Platform Prior to 17.4.8 and 17.10.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33229

    Post summary

    A new CVE (CVE‑2026‑33229) for arbitrary code execution in XWiki Platform versions before 17.4.8 and 17.10.1 is listed, but no proof‑of‑concept, exploit tool, active exploitation, or patch details are provided.

    0000023
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appxwikixwiki---

Explore more