Directory Traversal Vulnerability in XWiki Platform by XWiki
CVE-2026-34151

8.2HIGH

Key Information:

Vendor

Xwiki

Vendor
CVE Published:
14 September 2026

What is CVE-2026-34151?

The XWiki Platform is susceptible to a directory traversal vulnerability due to improper handling of resource requests in the /skin/ action. Prior to versions 17.10.5 and 18.2.0, an unauthenticated attacker could exploit this issue to read sensitive files outside the expected resource directories, including configuration files and potentially sensitive host files. This issue arises when Jetty 12 decodes request paths in a way that allows navigating up directory trees. The vulnerability has been addressed in the aforementioned versions to enhance security.

Affected Version(s)

xwiki-platform < 17.10.5 < 17.10.5

xwiki-platform >= 18.0.0-rc-1, < 18.2.0 < 18.0.0-rc-1, 18.2.0

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.