CVE-2026-48048: CWE-359: Exposure of Private Personal Information to an Unauthorized Actor in xwiki xwiki-platform
A vulnerability in XWiki Platform versions prior to 16.10.17, 17.4.9, 17.10.13, and including 18.0.0-rc1 allows unauthorized actors to extract password hashes one bit at a time via modified parameters to the LiveTableResults feature. This exposure enables retrieval of full password salts and hashes after multiple requests. The issue stems from insufficient patching of a previous vulnerability (GHSA-5cf8-vrr8-8hjm). The vulnerability is addressed by adjustments made starting in versions 18.0.0RC1, 17.10.13, 17.4.9, and 16.10.17, and a manual patch workaround is available for the LiveTableResultsMacros wiki page.
AI Analysis
Technical Summary
XWiki Platform suffers from a CWE-359 vulnerability where private personal information, specifically password hashes and salts, can be exposed to unauthorized actors. The flaw exists in versions starting from 6.2.1 up to but not including 16.10.17, 17.4.9, 17.10.13, and including 18.0.0-rc1. Attackers can exploit slightly modified parameters to the LiveTableResults feature to extract password hashes bit by bit, requiring approximately 768 requests to retrieve the full hash and salt. The vulnerability is a result of an insufficient patch for a prior issue (GHSA-5cf8-vrr8-8hjm). The vendor has adjusted the checks for password and email properties in the specified fixed versions. A manual patch can be applied to the XWiki.LiveTableResultsMacros wiki page as a workaround.
Potential Impact
An attacker with network access can retrieve password hashes and salts of users by exploiting the LiveTableResults feature, potentially enabling offline password cracking. The vulnerability does not affect integrity or availability but compromises confidentiality of sensitive authentication data. The CVSS score of 7.5 reflects a high severity due to network attack vector, no required privileges or user interaction, and high confidentiality impact.
Mitigation Recommendations
The vulnerability is fixed in XWiki Platform versions 16.10.17, 17.4.9, 17.10.13, and 18.0.0RC1 and later. Users should upgrade to one of these versions or later to remediate the issue. As a workaround, the patch can be manually applied to the XWiki.LiveTableResultsMacros wiki page to prevent exposure. No official vendor advisory or patch link is provided, so users should verify patch availability and instructions from the official XWiki sources.
CVE-2026-48048: CWE-359: Exposure of Private Personal Information to an Unauthorized Actor in xwiki xwiki-platform
Description
A vulnerability in XWiki Platform versions prior to 16.10.17, 17.4.9, 17.10.13, and including 18.0.0-rc1 allows unauthorized actors to extract password hashes one bit at a time via modified parameters to the LiveTableResults feature. This exposure enables retrieval of full password salts and hashes after multiple requests. The issue stems from insufficient patching of a previous vulnerability (GHSA-5cf8-vrr8-8hjm). The vulnerability is addressed by adjustments made starting in versions 18.0.0RC1, 17.10.13, 17.4.9, and 16.10.17, and a manual patch workaround is available for the LiveTableResultsMacros wiki page.
CVSS v3.1
Score 7.5high
Affected software
pkg:maven/org.xwiki/xwiki-platformRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
XWiki Platform suffers from a CWE-359 vulnerability where private personal information, specifically password hashes and salts, can be exposed to unauthorized actors. The flaw exists in versions starting from 6.2.1 up to but not including 16.10.17, 17.4.9, 17.10.13, and including 18.0.0-rc1. Attackers can exploit slightly modified parameters to the LiveTableResults feature to extract password hashes bit by bit, requiring approximately 768 requests to retrieve the full hash and salt. The vulnerability is a result of an insufficient patch for a prior issue (GHSA-5cf8-vrr8-8hjm). The vendor has adjusted the checks for password and email properties in the specified fixed versions. A manual patch can be applied to the XWiki.LiveTableResultsMacros wiki page as a workaround.
Potential Impact
An attacker with network access can retrieve password hashes and salts of users by exploiting the LiveTableResults feature, potentially enabling offline password cracking. The vulnerability does not affect integrity or availability but compromises confidentiality of sensitive authentication data. The CVSS score of 7.5 reflects a high severity due to network attack vector, no required privileges or user interaction, and high confidentiality impact.
Mitigation Recommendations
The vulnerability is fixed in XWiki Platform versions 16.10.17, 17.4.9, 17.10.13, and 18.0.0RC1 and later. Users should upgrade to one of these versions or later to remediate the issue. As a workaround, the patch can be manually applied to the XWiki.LiveTableResultsMacros wiki page to prevent exposure. No official vendor advisory or patch link is provided, so users should verify patch availability and instructions from the official XWiki sources.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-20T18:15:53.578Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a79f842bf8831d5390a44b8
Added to database: 08/10/2026, 16:11:46 UTC
Last enriched: 08/10/2026, 16:26:25 UTC
Last updated: 08/10/2026, 17:45:08 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.