CVE-2026-34151
CVE-2026-34151 is a high-severity vulnerability with a CVSS 4.0 base score of 8.2. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-24.
Key facts
- Severity: High (CVSS 4.0 base score 8.2)
- EPSS exploit prediction: 1% (63rd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-24
- Published:
- Last modified:
Description
XWiki Platform is a generic wiki platform. Prior to 17.10.5 and 18.2.0, the /skin/ action in com.xpn.xwiki.web.SkinAction can resolve double-encoded parent-directory segments outside the intended skin or web-application resource prefix when Jetty 12 or later decodes the request path. The affected lookup is replaced with Environment.getResourceAsStream(String, String), which constrains a resource to its expected prefix. An unauthenticated remote attacker can use the vulnerable behavior to read arbitrary resources permitted to the Jetty process, including WEB-INF/xwiki.cfg and, depending on deployment depth and operating-system permissions, host files. Tomcat and Jetty versions before 12 do not appear affected. This issue is fixed in versions 17.10.5 and 18.2.0.
Frequently asked questions
- What is CVE-2026-34151?
- XWiki Platform is a generic wiki platform. Prior to 17.10.5 and 18.2.0, the /skin/ action in com.xpn.xwiki.web.SkinAction can resolve double-encoded parent-directory segments outside the intended skin or web-application resource prefix when Jetty 12 or later decodes the request path. The affected lookup is replaced with Environment.getResourceAsStream(String, String), which constrains a resource to its expected prefix. An unauthenticated remote attacker can use the vulnerable behavior to read arbitrary resources permitted to the Jetty process, including WEB-INF/xwiki.cfg and, depending on deployment depth and operating-system permissions, host files. Tomcat and Jetty versions before 12 do not appear affected. This issue is fixed in versions 17.10.5 and 18.2.0.
- How severe is CVE-2026-34151?
- CVE-2026-34151 has a CVSS 4.0 base score of 8.2, rated high severity.
- Is CVE-2026-34151 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (63rd percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-34151?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2026-34151 published?
- CVE-2026-34151 was published on 2026-09-14 and last updated on 2026-09-30.
References
- https://github.com/xwiki/xwiki-commons/pull/1675
- https://github.com/xwiki/xwiki-platform/commit/79eba8655f3a96021a8e7ad07956e48d20a82383
- https://github.com/xwiki/xwiki-platform/commit/f7b33704083d3b4e45d1b9fc1e2cc33c66855f85
- https://github.com/xwiki/xwiki-platform/releases/tag/xwiki-platform-17.10.5
- https://github.com/xwiki/xwiki-platform/releases/tag/xwiki-platform-18.2.0
- https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-qj4x-9g63-25g6
- https://jira.xwiki.org/browse/XCOMMONS-3594
- https://jira.xwiki.org/browse/XWIKI-24075
Other CWE-24 vulnerabilities
- CVE-2026-39813 — Critical (CVSS 9.8): A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through…
- CVE-2026-49103 — Critical (CVSS 9.4): Webmin before 2.640 does not safely construct a filename for saving of an attachment within the mailboxes component.…
- CVE-2025-61318 — Critical (CVSS 9.1): Emlog Pro 2.5.20 has an arbitrary file deletion vulnerability. This vulnerability stems from the admin/template.php…
- CVE-2023-6699 — Critical (CVSS 9.1): The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to Directory Traversal in all…
- CVE-2025-54769 — High (CVSS 8.8): An authenticated, read-only user can upload a file and perform a directory traversal to have the uploaded file placed…
- CVE-2025-60344 — High (CVSS 8.6): A path traversal (directory traversal) vulnerability in D-Link DSR series routers allows unauthenticated remote…