CVE-2026-34151
XWiki Platform is a generic wiki platform. Prior to 17.10.5 and 18.2.0, the /skin/ action in com.xpn.xwiki.web.SkinAction can resolve double-encoded parent-directory segments outside the intended skin or web-application resource prefix when Jetty 12 or later decodes the request path. The affected lookup is replaced with Environment.getResourceAsStream(String, String), which constrains a resource to its expected prefix. An unauthenticated remote attacker can use the vulnerable behavior to read arbitrary resources permitted to the Jetty process, including WEB-INF/xwiki.cfg and, depending on deployment depth and operating-system permissions, host files. Tomcat and Jetty versions before 12 do not appear affected. This issue is fixed in versions 17.10.5 and 18.2.0.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.2
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.54%
- CWE
- CWE-24
- Published
- 2026-09-14
- Last modified
- 2026-09-14
Affected products
- xwiki xwiki-platform
- xwiki xwiki-platform
Weakness type
Related vulnerabilities
- CVE-2025-27920 — Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling. By us
- CVE-2024-6746 — NaiboWang EasySpider HTTP GET Request server.js path traversal
- CVE-2023-52076 — Remote Code Execution Vulnerability in Atril's EPUB ebook parsing
- CVE-2026-39813 — A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.
- CVE-2025-53513 — Zip slip vulnerability in Juju
- CVE-2024-23657 — Path Traversal: '../filedir' in Nuxt Devtools
- CVE-2021-26725 — Authenticated command path traversal on timezone settings in Guardian/CMC before 20.0.7.4
- CVE-2025-60344 — A path traversal (directory traversal) vulnerability in D-Link DSR series routers allows unauthenticated remote attacker