What is CVE-2026-48047?
A path traversal vulnerability in XWiki Platform's WebJars API allows an attacker with a malicious WebJar extension to write arbitrary files on the wiki. It affects versions 9.6-rc-1 up to before 16.10.17, 17.4.9, and 17.10.3. Users should upgrade to the fixed versions.
Azərbaycanca: XWiki platformunun WebJars API paketində yol keçidi (path traversal) zəifliyi aşkarlanıb. Bu, zərərli WebJar uzantısı quraşdıra bilən hücumçuya wiki üzərində icazəsiz fayl yazma imkanı verir. XWiki-ni 16.10.17, 17.4.9, 17.10.3 və ya daha yuxarı versiyalara yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
What can CVE-2026-48047 allow an attacker to do in XWiki?
This path traversal vulnerability allows an attacker with a malicious WebJar extension to write arbitrary files on the wiki.
Which XWiki versions should be upgraded to for protection against CVE-2026-48047?
Users should upgrade to versions 16.10.17, 17.4.9, 17.10.3 or above.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.