CVE-2026-48048: CWE-359: Exposure of Private Personal Information to an Unauthorized Actor in xwiki xwiki-platform
XWiki Platform is a generic wiki platform. XWiki discovered that the patch for GHSA-5cf8-vrr8-8hjm was insufficient. Starting with version 6.2.1 and prior to versions 18.0.0RC1, 17.10.13, 17.4.9 and 16.10.17, with slightly modified parameters to the `LiveTableResults`, it is still possible to discover password hashes one bit at a time, so with 768 requests, the full password salt and hash can be retrieved of a user. The check for password (and email properties) has been adjusted in XWiki 18.0.0RC1, 17.10.13, 17.4.9 and 16.10.17. As a workaround, the patch can be applied manually to the wiki page `XWiki.LiveTableResultsMacros`.
AI Analysis
Technical Summary
XWiki Platform suffers from a CWE-359 vulnerability where private personal information, specifically password hashes and salts, can be exposed to unauthorized actors. The flaw exists in versions starting from 6.2.1 up to but not including 16.10.17, 17.4.9, 17.10.13, and including 18.0.0-rc1. Attackers can exploit slightly modified parameters to the LiveTableResults feature to extract password hashes bit by bit, requiring approximately 768 requests to retrieve the full hash and salt. The vulnerability is a result of an insufficient patch for a prior issue (GHSA-5cf8-vrr8-8hjm). The vendor has adjusted the checks for password and email properties in the specified fixed versions. A manual patch can be applied to the XWiki.LiveTableResultsMacros wiki page as a workaround.
Potential Impact
An attacker with network access can retrieve password hashes and salts of users by exploiting the LiveTableResults feature, potentially enabling offline password cracking. The vulnerability does not affect integrity or availability but compromises confidentiality of sensitive authentication data. The CVSS score of 7.5 reflects a high severity due to network attack vector, no required privileges or user interaction, and high confidentiality impact.
Mitigation Recommendations
The vulnerability is fixed in XWiki Platform versions 16.10.17, 17.4.9, 17.10.13, and 18.0.0RC1 and later. Users should upgrade to one of these versions or later to remediate the issue. As a workaround, the patch can be manually applied to the XWiki.LiveTableResultsMacros wiki page to prevent exposure. No official vendor advisory or patch link is provided, so users should verify patch availability and instructions from the official XWiki sources.
CVE-2026-48048: CWE-359: Exposure of Private Personal Information to an Unauthorized Actor in xwiki xwiki-platform
Description
XWiki Platform is a generic wiki platform. XWiki discovered that the patch for GHSA-5cf8-vrr8-8hjm was insufficient. Starting with version 6.2.1 and prior to versions 18.0.0RC1, 17.10.13, 17.4.9 and 16.10.17, with slightly modified parameters to the `LiveTableResults`, it is still possible to discover password hashes one bit at a time, so with 768 requests, the full password salt and hash can be retrieved of a user. The check for password (and email properties) has been adjusted in XWiki 18.0.0RC1, 17.10.13, 17.4.9 and 16.10.17. As a workaround, the patch can be applied manually to the wiki page `XWiki.LiveTableResultsMacros`.
CVSS v3.1
Score 7.5high
Affected software
xwiki
xwiki-platform
pkg:maven/org.xwiki/xwiki-platformRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
XWiki Platform suffers from a CWE-359 vulnerability where private personal information, specifically password hashes and salts, can be exposed to unauthorized actors. The flaw exists in versions starting from 6.2.1 up to but not including 16.10.17, 17.4.9, 17.10.13, and including 18.0.0-rc1. Attackers can exploit slightly modified parameters to the LiveTableResults feature to extract password hashes bit by bit, requiring approximately 768 requests to retrieve the full hash and salt. The vulnerability is a result of an insufficient patch for a prior issue (GHSA-5cf8-vrr8-8hjm). The vendor has adjusted the checks for password and email properties in the specified fixed versions. A manual patch can be applied to the XWiki.LiveTableResultsMacros wiki page as a workaround.
Potential Impact
An attacker with network access can retrieve password hashes and salts of users by exploiting the LiveTableResults feature, potentially enabling offline password cracking. The vulnerability does not affect integrity or availability but compromises confidentiality of sensitive authentication data. The CVSS score of 7.5 reflects a high severity due to network attack vector, no required privileges or user interaction, and high confidentiality impact.
Mitigation Recommendations
The vulnerability is fixed in XWiki Platform versions 16.10.17, 17.4.9, 17.10.13, and 18.0.0RC1 and later. Users should upgrade to one of these versions or later to remediate the issue. As a workaround, the patch can be manually applied to the XWiki.LiveTableResultsMacros wiki page to prevent exposure. No official vendor advisory or patch link is provided, so users should verify patch availability and instructions from the official XWiki sources.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-20T18:15:53.578Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a79f842bf8831d5390a44b8
Added to database: 08/10/2026, 16:11:46 UTC
Last enriched: 08/10/2026, 16:26:25 UTC
Last updated: 09/23/2026, 13:47:45 UTC
Views: 58
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.