XWiki Platform Unauthenticated XAR Import Vulnerability via REST API

Vulnerability

A vulnerability exists in XWiki Platform versions prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17, allowing unauthenticated users to import XAR files through the POST /wikis/{wikiName} API. This import is executed without any authentication or authorization checks, enabling attackers to create or modify documents within the targeted wiki. The issue arises from a removal of an indirect admin rights check in a previous update, which now allows guest users to import XAR files that could grant them additional privileges, such as programming rights.

Impact

Exploitation of this vulnerability allows for unauthorized XAR imports, which can be used to create or update wiki pages, potentially including sensitive preference pages that grant additional rights.

Reproduction

The vulnerability can be reproduced by sending a POST request to the /wikis/{wikiName} endpoint without authentication. This can be done using a tool like Postman or through a script that automates the HTTP request. The request must include the XAR file to be imported.

Remediation

Users can upgrade to XWiki versions 16.10.17, 17.4.9, 17.10.3, 18.0.1 or 18.1.0-rc-1 to address this vulnerability.

Added: May 20, 2026, 8:58 PM
Updated: May 20, 2026, 8:58 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
8.4
remediation
0.0
relevance
8.4
threat
4.8
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.