9.3
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/SC:N/VI:H/SI:N/VA:H/SA:N
Description
CVE-2026-33137 XWiki Platform - Unauthenticated XAR Import via REST /wikis/wikiName Description The POST /wikis/wikiName REST API endpoint in XWiki Platform executes a XAR XWiki Archive import without performing any authentication or authorization...
Basic Information
ID
6A54DAD9-2BC4-566C-ADCD-9042F845AEC0
Published
May 25, 2026 at 18:10
Modified
May 25, 2026 at 18:11