GHSA-8cw6-4r32-6r3h · Severity: critical · Ecosystem: maven — XWiki Platform may allow privilege escalation to programming rights via user's first name
XWiki Commons are technical libraries common to several other top level XWiki projects. Starting in version 3.1-milestone-1, any user can edit their own profile and inject code, which is going to be executed with programming right. The same vulnerability can also be exploited in all other places where short text properties are displayed, e.g., in apps created using Apps Within Minutes that use a short text field. The problem has been patched on versions 13.10.9, 14.4.4, 14.7RC1.
Conclusion & alert: CVE-2023-26055 is rated High Exploit Risk (72.9/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 1.16%). Core evidence: 3 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 4.90% | 1.16% | -3.73% |
| 2 | 2026-03-14 | 5.05% | 4.90% | -0.16% |
| 3 | 2026-03-07 | — | 5.05% | — |
Full EPSS history (18 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.9 | 3.1 | CRITICAL |
|
3.1 | 6.0 | [email protected] |
| 9.9 | 3.1 | CRITICAL |
|
3.1 | 6.0 | [email protected] |
GHSA-8cw6-4r32-6r3h · Severity: critical · Ecosystem: maven — XWiki Platform may allow privilege escalation to programming rights via user's first name
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| xwiki | commons | >= 3.2, < 13.10.9 | cpe:2.3:a:xwiki:commons:*:*:*:*:*:*:*:* |
| xwiki | commons | >= 14.4, < 14.4.4 | cpe:2.3:a:xwiki:commons:*:*:*:*:*:*:*:* |
| xwiki | commons | >= 14.5, < 14.7 | cpe:2.3:a:xwiki:commons:*:*:*:*:*:*:*:* |
| xwiki | commons | 3.1 | cpe:2.3:a:xwiki:commons:3.1:milestone1:*:*:*:*:*:* |
| xwiki | commons | 3.1 | cpe:2.3:a:xwiki:commons:3.1:milestone2:*:*:*:*:*:* |
| xwiki | commons | 3.1.1 | cpe:2.3:a:xwiki:commons:3.1.1:*:*:*:*:*:*:* |
| xwiki | commons | 14.4 | cpe:2.3:a:xwiki:commons:14.4:rc1:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/xwiki/xwiki-commons/security/advisories/GHSA-8cw6-4r32-6r3h | Exploit Vendor Advisory |
| https://jira.xwiki.org/browse/XCOMMONS-2498 | Issue Tracking Patch Vendor Advisory |
| https://jira.xwiki.org/browse/XWIKI-19793 | Exploit Issue Tracking Patch Vendor Advisory |
| https://jira.xwiki.org/browse/XWIKI-19794 | Exploit Issue Tracking Patch Vendor Advisory |