An unauthenticated attacker can create or update documents in the target XWiki instance by exploiting the XAR import functionality through the `/wikis/{wikiName}` REST endpoint due to missing authentication and authorization checks, as detailed in CVE-2026-33137.
PoC
xwiki-platform-rest-server +1
xwiki
xar
unauthenticated
rce
cve-2026-33137
3r
3t
1c
updated