CVE-2026-48047Disclosure

LOWCVSS 5.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

XWiki Platform WebJars API is a package for XWiki, a generic wiki platform. Starting with version 9.6-rc-1 and prior to versions 16.10.17, 17.4.9, and 17.10.3, a potential path traversal vulnerability allow an attacker who manages to get a malicious WebJar extension installed on the wiki to write arbitrary files. While the consequences could be severe like overriding configuration files and setting the superadmin password, the attack first requires that the attacker already has admin access to at least a subwiki to be able to install a malicious extension. Further, the attacker needs to publish a malicious extension in an extension repository that is configured in the instance. This vulnerability has been patched in XWiki 16.10.17, 17.4.9, 17.10.3, and 18.0.0RC1. XWiki is not aware of any workarounds except for being careful whom developers grant script and admin rights to.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-24

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-08-08); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-08: 1Mentions · 2026-08-09: 1Patch / Workaround · 2026-08-09: 1Technical Details · 2026-08-08: 1Technical Details · 2026-08-09: 108-0808-09
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-08-081
Disclosure1
2026-08-091
Patch1
Full discourse2 posts
  • CyberSignal | Cybersecurity News@XQOPTRX
    Patch

    📝 XWiki path traversal can overwrite server files CVE-2026-48047 affects multiple XWiki releases. An attacker who already has sufficient wiki administration privileges and can install a malicious WebJar extension could write files outside the intended directory—including potentially sensitive configuration files. Patched in 16.10.17, 17.4.9, 17.10.3 and 18.0.0RC1. 🔎 Source: XWiki / GitHub / CVE #XWiki #PathTraversal #CVE #WebSecurity #CyberSecurity

    Post summary

    The post announces a path traversal vulnerability in XWiki (CVE‑2026‑48047), details its technical aspects, and provides patch versions, without mentioning PoC or active exploitation.

    0000051
    34 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-48047 XWiki Platform WebJars API is a package for XWiki, a generic wiki platform. Starting with version 9.6-rc-1 and prior to versions 16.10.17, 17.4.9, and 17.10.3, a pote… https://www.cve.org/CVERecord?id=CVE-2026-48047

    Post summary

    The tweet announces CVE-2026-48047, describing the affected XWiki WebJars API and vulnerable versions, but does not provide any PoC, exploit code, patch, or evidence of active exploitation.

    000001.4K
    57.9K followersView on X

Explore more