---
id: CVE-2026-33137
title: >-
  XWiki Platform is a generic wiki platform offering runtime services for
  applications built on top of it
summary: >-
  XWiki Platform is a generic wiki platform offering runtime services for
  applications built on top of it. XWiki Platform is a generic wiki platform. In
  versions starting with 15.10.6 and prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and
  16.10.17…
severity: none
cwe:
  - CWE-862
published: '2026-05-20'
updated: '2026-07-23'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-33137'
references:
  - url: >-
      https://github.com/xwiki/xwiki-platform/commit/4b7b95b79256374d487e9ece1dc48f527966990f
    label: security-advisories@github.com
  - url: >-
      https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-qrvh-r3f2-9h4r
    label: security-advisories@github.com
  - url: 'https://jira.xwiki.org/browse/XWIKI-23953'
    label: security-advisories@github.com
tags:
  - nvd
  - exploit-available
epss: 0.00594
epssPercentile: 0.47135
ingestedAt: '2026-07-23T13:18:08.661Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/portbuster1337/CVE-2026-33137'
  checkedAt: '2026-09-24T07:53:02.310Z'
exploitAvailable: true
---

## Overview

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform is a generic wiki platform. In versions starting with 15.10.6 and prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17, the POST /wikis/{wikiName} API executes a XAR import without performing any authentication or authorization checks, allowing an unauthenticated attacker to create or update documents in the target wiki. This vulnerability has been patched in XWiki 16.10.17, 17.4.9, 17.10.3, 18.0.1 and 18.1.0-rc-1.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
