<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>XWiki (All Versions Prior to Patch) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/xwiki-all-versions-prior-to-patch/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 21 Sep 2026 13:51:00 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/xwiki-all-versions-prior-to-patch/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Code Execution Vulnerability in XWiki</title><link>https://feed.craftedsignal.io/briefs/2026-09-xwiki-rce/</link><pubDate>Mon, 21 Sep 2026 13:51:00 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-xwiki-rce/</guid><description>An authenticated remote code execution vulnerability (CVE-2024-51751) in XWiki allows authenticated attackers to execute arbitrary code on the underlying host system.</description><content:encoded><![CDATA[<p>XWiki, an open-source enterprise wiki platform, contains a critical vulnerability identified as CVE-2024-51751. This flaw permits an authenticated remote attacker to execute arbitrary code within the context of the application. The vulnerability is triggered through the manipulation of user-supplied input that is insufficiently sanitized before processing, allowing the attacker to escape the expected application sandbox. Given the nature of XWiki's architecture, which often involves integrations with internal business processes and administrative functions, successful exploitation grants the attacker significant control over the application server. Defenders should focus on monitoring for unauthorized administrative access and suspicious system calls originating from the XWiki service account.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2024-51751 leads to a full system compromise, allowing an attacker to execute arbitrary commands, access sensitive data within the wiki, and potentially pivot into the internal network environment. The target scope includes any organization deploying XWiki instances where external or internal users hold valid (or low-privileged) credentials.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Patch XWiki instances to the latest version immediately to mitigate CVE-2024-51751.</li>
<li>Review XWiki access logs for unusual patterns of authenticated activity, particularly involving administrative or configuration-related endpoints.</li>
<li>Restrict access to the XWiki administration interface to trusted IP ranges or VPN-only access.</li>
<li>Implement EDR or audit logging on the XWiki host to monitor for unexpected process creation (e.g., cmd.exe, /bin/sh, or /usr/bin/python) originating from the web server application process.</li>
</ol>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category><category>vulnerability</category><category>rce</category><category>web-application</category></item></channel></rss>