CVE-2026-48048
7.5XWiki · xwiki-platform
The XWiki Platform contains a vulnerability leading to the exposure of private personal information to unauthorized actors through the livetable UI.
Executive summary
An information disclosure vulnerability in the XWiki Platform allows unauthenticated users to access private personal information, creating a significant data privacy risk.
Vulnerability
This is an exposure of private personal information (CWE-359) occurring within the livetable-ui component. An unauthenticated attacker can leverage this flaw to access sensitive user data without needing valid credentials.
Business impact
Successful exploitation allows unauthorized access to personally identifiable information (PII), which may trigger regulatory compliance violations such as GDPR or CCPA. With a CVSS score of 7.5, the potential for mass data harvesting makes this a high-priority issue that could lead to significant legal and operational consequences for the organization.
Remediation
Immediate Action: Update the affected XWiki instances to version 16.10.17, 17.4.9, or 17.10.3, as specified in the vendor security advisory.
Proactive Monitoring: Review audit logs for unusual patterns of access to user-related livetable queries or unexpected data exports.
Compensating Controls: Implement WAF filtering to intercept and block requests that attempt to traverse or query sensitive user-related API endpoints or table views.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
The exposure of sensitive personal information is a critical concern for any enterprise platform. Organizations should immediately verify their current XWiki version and apply the provided patches to ensure the protection of user data and maintain regulatory compliance.