CVE-2026-23734
Impact
It's possible to get access and read configuration files by using URLs such as http://localhost:8080/bin/ssx/Main/WebHome?resource=/../../WEB-INF/xwiki.cfg&minify=false.
This can apparently be reproduced on Tomcat instances.
Patches
This has been patched in 18.0.0-rc-1, 17.10.3, 17.4.9, 16.10.17.
Workarounds
There is no known workaround, other than upgrading XWiki.
References
- https://jira.xwiki.org/browse/XCOMMONS-3547
- https://github.com/xwiki/xwiki-commons/commit/a979cafd89f6a9c9c0b9ab19744d672df64429bf
For more information
If you have any questions or comments about this advisory:
- Open an issue in Jira XWiki.org
- Email us at Security Mailing List
Attribution
The vulnerability was reported by Michał Kołek.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/xwiki/xwiki-commons/security/advisories/GHSA-xq3r-2qv5-vqqm, https://nvd.nist.gov/vuln/detail/CVE-2026-23734, https://github.com/xwiki/xwiki-commons/commit/a979cafd89f6a9c9c0b9ab19744d672df64429bf, https://github.com/xwiki/xwiki-commons, https://jira.xwiki.org/browse/XCOMMONS-3547
