
XWiki CVE-2026-48048 is an incomplete-fix lesson: modified LiveTable requests can reconstruct password salt/hash data. Patch to a fixed branch and hunt for hundreds of changing requests aimed at user properties. https://nvd.nist.gov/vuln/detail/CVE-2026-48048
Post summary
The announcement highlights CVE‑2026‑48048 as an incomplete fix that enables reconstruction of password salts via modified LiveTable requests and notes a patch to the fixed branch, with no evidence of active exploitation or a PoC.
