CVE-2026-48048

7.5

XWiki · xwiki-platform

The XWiki Platform contains a vulnerability leading to the exposure of private personal information to unauthorized actors through the livetable UI.

Executive summary

An information disclosure vulnerability in the XWiki Platform allows unauthenticated users to access private personal information, creating a significant data privacy risk.

Vulnerability

This is an exposure of private personal information (CWE-359) occurring within the livetable-ui component. An unauthenticated attacker can leverage this flaw to access sensitive user data without needing valid credentials.

Business impact

Successful exploitation allows unauthorized access to personally identifiable information (PII), which may trigger regulatory compliance violations such as GDPR or CCPA. With a CVSS score of 7.5, the potential for mass data harvesting makes this a high-priority issue that could lead to significant legal and operational consequences for the organization.

Remediation

Immediate Action: Update the affected XWiki instances to version 16.10.17, 17.4.9, or 17.10.3, as specified in the vendor security advisory.

Proactive Monitoring: Review audit logs for unusual patterns of access to user-related livetable queries or unexpected data exports.

Compensating Controls: Implement WAF filtering to intercept and block requests that attempt to traverse or query sensitive user-related API endpoints or table views.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The exposure of sensitive personal information is a critical concern for any enterprise platform. Organizations should immediately verify their current XWiki version and apply the provided patches to ensure the protection of user data and maintain regulatory compliance.

More XWiki CVEs