We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-46557

Any user with view access to the XWiki space can change the authenticator



Description

XWiki is a generic wiki platform. In versions starting from 15.3-rc-1 to before 15.10.14, from 16.0.0-rc-1 to before 16.4.6, and from 16.5.0-rc-1 to before 16.10.0-rc-1, a user who can access pages located in the XWiki space (by default, anyone) can access the page XWiki.Authentication.Administration and (unless an authenticator is set in xwiki.cfg) switch to another installed authenticator. Note that, by default, there is only one authenticator available (Standard XWiki Authenticator). So, if no authenticator extension was installed, it's not really possible to do anything for an attacker. Also, in most cases, if an SSO authenticator is installed and utilized (like OIDC or LDAP for example), the worst an attacker can do is break authentication by switching back to the standard authenticator (that's because it's impossible to login to a user which does not have a stored password, and that's usually what SSO authenticator produce). This issue has been patched in versions 15.10.14, 16.4.6, and 16.10.0-rc-1.

Reserved 2025-04-24 | Published 2025-04-30 | Updated 2025-04-30 | Assigner GitHub_M


HIGH: 8.4CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N

Problem types

CWE-862: Missing Authorization

Product status

>= 15.3-rc-1, < 15.10.14
affected

>= 16.0.0-rc-1, < 16.4.6
affected

>= 16.5.0-rc-1, < 16.10.0-rc-1
affected

References

github.com/...atform/security/advisories/GHSA-f9c6-2f9p-82jj

github.com/...ommit/5efc31cea1501c9a5cb593566fea8b558ff32a2a

jira.xwiki.org/browse/XWIKI-22604

cve.org (CVE-2025-46557)

nvd.nist.gov (CVE-2025-46557)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-46557

Support options

Helpdesk Chat, Email, Knowledgebase