Description
XWiki Platform is a generic wiki platform. Prior to 17.10.5 and 18.2.0, the /skin/ action in com.xpn.xwiki.web.SkinAction can resolve double-encoded parent-directory segments outside the intended skin or web-application resource prefix when Jetty 12 or later decodes the request path. The affected lookup is replaced with Environment.getResourceAsStream(String, String), which constrains a resource to its expected prefix. An unauthenticated remote attacker can use the vulnerable behavior to read arbitrary resources permitted to the Jetty process, including WEB-INF/xwiki.cfg and, depending on deployment depth and operating-system permissions, host files. Tomcat and Jetty versions before 12 do not appear affected. This issue is fixed in versions 17.10.5 and 18.2.0.
Published: 2026-09-14
Score: 8.2 High
EPSS: 1.1% Low
KEV: No
Impact: Unprivileged Remote File Read via Path Traversal
Action: Immediate Patch
AI Analysis

Impact

A double‑encoded parent‑directory segment in the /skin/ action of XWiki Platform, when run on Jetty 12 or later, can resolve to files outside of the intended skin or web‑application resource prefix. The vulnerable logic uses Environment.getResourceAsStream(String, String), which limits lookups to resources with the expected prefix but is bypassed by improper path decoding. This enables an unauthenticated remote attacker to read arbitrary resources that the Jetty process can access, such as the WEB‑INF/xwiki.cfg configuration file or, depending on the deployment depth and operating‑system permissions, host files. The vulnerability is a classic directory traversal flaw identified as CWE‑24 and does not require authentication or elevated privileges to exploit.

Affected Systems

XWiki Platform releases prior to 17.10.5 and 18.2.0 are affected when deployed with Jetty 12 or newer. Versions using Tomcat or Jetty before 12 are not impacted. This issue is fixed in XWiki Platform 17.10.5 and 18.2.0 and later releases.

Risk and Exploitability

The CVSS score of 8.2 classifies this vulnerability as high severity. The EPSS score is <1%, indicating a very low but nonzero probability of exploitation. KEV is not listed, so there is no known public exploit at the time of reporting. The vulnerability is easy to trigger over the network by making a crafted request to the /skin/ endpoint, allowing an unauthenticated attacker to read arbitrary resources that the Jetty process can access.

Generated by OpenCVE AI on September 20, 2026 at 23:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade XWiki Platform to version 17.10.5, 18.2.0, or later. Ensure Jetty is 12 or newer.
  • If an upgrade cannot be performed immediately, block or drop requests to the /skin/ endpoint that contain double‑encoded parent‑directory sequences, or use a reverse proxy or web‑application firewall to sanitize path segments.
  • Restrict file system permissions so that the Jetty process has no read access to sensitive host files; limit the device’s read scope to the web application directory tree.

Generated by OpenCVE AI on September 20, 2026 at 23:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-qj4x-9g63-25g6 XWiki Platform Old Core: Resource path traversal via /skin/ action endpoint in Jetty 12+
History

Tue, 15 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
First Time appeared Xwiki
Xwiki xwiki-platform
Vendors & Products Xwiki
Xwiki xwiki-platform

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description XWiki Platform is a generic wiki platform. Prior to 17.10.5 and 18.2.0, the /skin/ action in com.xpn.xwiki.web.SkinAction can resolve double-encoded parent-directory segments outside the intended skin or web-application resource prefix when Jetty 12 or later decodes the request path. The affected lookup is replaced with Environment.getResourceAsStream(String, String), which constrains a resource to its expected prefix. An unauthenticated remote attacker can use the vulnerable behavior to read arbitrary resources permitted to the Jetty process, including WEB-INF/xwiki.cfg and, depending on deployment depth and operating-system permissions, host files. Tomcat and Jetty versions before 12 do not appear affected. This issue is fixed in versions 17.10.5 and 18.2.0.
Title XWiki Platform: Resource path traversal via /skin/ action endpoint in Jetty 12+
Weaknesses CWE-24
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Xwiki Xwiki-platform
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T18:56:11.951Z

Reserved: 2026-03-25T20:12:04.196Z

Link: CVE-2026-34151

cve-icon Vulnrichment

Updated: 2026-09-14T18:56:07.351Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T18:17:47.107

Modified: 2026-09-30T19:57:08.043

Link: CVE-2026-34151

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:00:08Z

Weaknesses
  • CWE-24

    Path Traversal: '../filedir'