HIGH

CVE-2023-26475

CVSS v3

8.8

HIGH

EPSS Score

23.6%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

XWiki Platform is a generic wiki platform. Starting in version 2.3-milestone-1, the annotation displayer does not execute the content in a restricted context. This allows executing anything with the right of the author of any document by annotating the document. This has been patched in XWiki 13.10.11, 14.4.7 and 14.10. There is no easy workaround except to upgrade.

Technical details

Published
3/2/2023

Frequently asked questions

What is CVE-2023-26475?

XWiki Platform is a generic wiki platform. Starting in version 2.3-milestone-1, the annotation displayer does not execute the content in a restricted context. This allows executing anything with the right of the author of any document by annotating the document. This has been patched in XWiki 13.10.11, 14.4.7 and 14.10. There is no easy workaround except to upgrade.

Is CVE-2023-26475 actively exploited?

Active exploitation of CVE-2023-26475 has not been confirmed. The EPSS score is 23.6%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2023-26475?

CVE-2023-26475 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2023-26475 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.