{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/xwiki-platform-rest-server/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"id":"CVE-2026-33137"}],"_cs_exploited":false,"_cs_has_poc":true,"_cs_poc_references":["https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-PORTBUSTER1337-CVE-2026-33137\u0026utm_source=rss\u0026utm_medium=rss"],"_cs_products":["xwiki-platform-rest-server"],"_cs_severities":["critical"],"_cs_tags":["xwiki","xar","unauthenticated","rce","cve-2026-33137"],"_cs_type":"advisory","_cs_vendors":["XWiki"],"content_html":"\u003cp\u003eXWiki is susceptible to an unauthenticated XAR import vulnerability, identified as CVE-2026-33137, affecting versions 15.10.6 before 16.10.17, 17.0.0-rc-1 before 17.4.9, 17.5.0 before 17.10.3, and 18.0.0-rc-1 before 18.1.0-rc-1. The vulnerability resides in the \u003ccode\u003e/wikis/{wikiName}\u003c/code\u003e REST endpoint, which allows for the execution of XAR imports without proper authentication or authorization checks. This flaw allows an attacker to create or modify documents within the target wiki instance, potentially leading to arbitrary code execution or data manipulation. Defenders should prioritize patching vulnerable XWiki installations or implementing HTTP proxy rules to mitigate this risk.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker identifies a vulnerable XWiki instance with an exposed \u003ccode\u003e/wikis/{wikiName}\u003c/code\u003e REST endpoint.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious XAR file containing payloads to create or modify documents.\u003c/li\u003e\n\u003cli\u003eThe attacker sends an HTTP POST request to the \u003ccode\u003e/wikis/{wikiName}\u003c/code\u003e endpoint, including the malicious XAR file in the request body.\u003c/li\u003e\n\u003cli\u003eThe XWiki instance processes the request without authentication or authorization.\u003c/li\u003e\n\u003cli\u003eThe XAR file is imported, leading to the creation or modification of documents within the specified wiki.\u003c/li\u003e\n\u003cli\u003eThe attacker gains unauthorized access to the modified documents.\u003c/li\u003e\n\u003cli\u003eThe attacker leverages the modified documents to execute arbitrary code or manipulate data within the XWiki instance.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-33137 allows unauthenticated attackers to create, modify, or delete content within the XWiki platform. This can lead to complete compromise of the XWiki instance, including unauthorized data access, data manipulation, and potentially arbitrary code execution on the server. The impact is significant, particularly for organizations relying on XWiki for critical knowledge management and collaboration.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade XWiki installations to patched versions: 16.10.17, 17.4.9, 17.10.3, 18.0.1, or 18.1.0-rc-1 to address CVE-2026-33137.\u003c/li\u003e\n\u003cli\u003eImplement an HTTP proxy rule to block POST requests to the \u003ccode\u003e/wikis/{wikiName}\u003c/code\u003e endpoint as a temporary workaround.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule \u0026quot;Detect XWiki Unauthenticated XAR Import via REST API\u0026quot; to identify exploitation attempts in web server logs.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for suspicious POST requests to the \u003ccode\u003e/wikis/{wikiName}\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-27T00:35:46Z","date_published":"2026-05-26T18:59:47Z","id":"https://feed.craftedsignal.io/briefs/2026-05-xwiki-xar-import/","summary":"An unauthenticated attacker can create or update documents in the target XWiki instance by exploiting the XAR import functionality through the `/wikis/{wikiName}` REST endpoint due to missing authentication and authorization checks, as detailed in CVE-2026-33137.","title":"XWiki Unauthenticated XAR Import via REST API","url":"https://feed.craftedsignal.io/briefs/2026-05-xwiki-xar-import/"}],"language":"en","title":"CraftedSignal Threat Feed - Xwiki-Platform-Rest-Server","version":"https://jsonfeed.org/version/1.1"}