Skip to main content
Vulnerability Database/CVE-2026-34151

CVE-2026-34151: XWiki Platform Path Traversal Vulnerability

CVE-2026-34151 is a path traversal vulnerability in XWiki Platform that allows unauthenticated attackers to read arbitrary files. This post covers technical details, affected versions, impact, and mitigation.

Published:

CVE-2026-34151 Overview

CVE-2026-34151 is a path traversal vulnerability [CWE-24] in the XWiki Platform, a generic wiki platform written in Java. The flaw resides in the /skin/ action handled by com.xpn.xwiki.web.SkinAction. When XWiki runs behind Jetty 12 or later, the action resolves double-encoded parent-directory segments and escapes the intended skin or web-application resource prefix. An unauthenticated remote attacker can read arbitrary resources accessible to the Jetty process, including WEB-INF/xwiki.cfg. Depending on deployment depth and operating-system permissions, host files outside the web application may also be exposed. Tomcat deployments and Jetty releases prior to version 12 do not appear affected.

Critical Impact

Unauthenticated attackers can retrieve sensitive server-side files, including XWiki configuration containing credentials and secrets.

Affected Products

  • XWiki Platform versions prior to 17.10.5
  • XWiki Platform 18.x versions prior to 18.2.0
  • Deployments running on Jetty 12 or later

Discovery Timeline

  • 2026-09-14 - CVE-2026-34151 published to NVD
  • 2026-09-14 - Last updated in NVD database

Technical Details for CVE-2026-34151

Vulnerability Analysis

The /skin/ action in com.xpn.xwiki.web.SkinAction was designed to serve skin resources from within the XWiki web application. When Jetty 12 or later decodes the incoming request path, it normalizes previously encoded segments that older container versions left encoded. This normalization allows double-encoded ../ sequences to reach the skin lookup logic already resolved as parent-directory traversals.

Because the lookup used raw path resolution via java.nio.file.Path and Paths, it followed those traversals outside the intended prefix. Attackers can request paths that resolve to WEB-INF/xwiki.cfg, deployment descriptors, or, depending on filesystem permissions, files elsewhere on the host readable by the Jetty user.

Root Cause

The root cause is unsafe resource resolution in AbstractResourceSkin combined with a path-decoding behavior change in Jetty 12. The prior implementation resolved resource paths using filesystem Path operations that were not constrained to the skin prefix. The fix replaces this with Environment.getResourceAsStream(String, String), which enforces that a resource remains within its expected prefix.

Attack Vector

Exploitation requires only network access to the XWiki HTTP endpoint. No authentication or user interaction is needed. An attacker issues a crafted HTTP GET request to the /skin/ endpoint containing double-encoded parent-directory sequences (for example, %252e%252e%252f). Jetty 12 decodes the outer encoding, and the SkinAction handler then resolves the resulting traversal against the servlet resource tree.

java
// Patch excerpt: xwiki-platform-oldcore/.../internal/skin/AbstractResourceSkin.java
 package com.xpn.xwiki.internal.skin;
 
 import java.net.URL;
-import java.nio.file.Path;
-import java.nio.file.Paths;
 
 import org.apache.commons.configuration2.BaseConfiguration;
 import org.apache.commons.configuration2.Configuration;

// Patch excerpt: xwiki-platform-oldcore/.../XWiki.java
 import org.xwiki.container.servlet.HttpServletUtils;
 import org.xwiki.context.Execution;
 import org.xwiki.edit.EditConfiguration;
+import org.xwiki.environment.Environment;
 import org.xwiki.extension.CoreExtension;
 import org.xwiki.extension.job.internal.InstallJob;
 import org.xwiki.extension.job.internal.UninstallJob;

Source: XWiki Platform commit 79eba86

Detection Methods for CVE-2026-34151

Indicators of Compromise

  • HTTP GET requests to /skin/ paths containing double-encoded traversal tokens such as %252e%252e%252f or mixed-case variants.
  • Access log entries showing 200 responses to /skin/ requests that reference WEB-INF/xwiki.cfg, web.xml, or resource paths outside the active skin directory.
  • Unexpected outbound reads of configuration files or credentials shortly after /skin/ request bursts from a single client.

Detection Strategies

  • Inspect Jetty access logs for /skin/ request URIs containing %25 sequences followed by 2e2e or %2e%2e.
  • Correlate HTTP responses on the /skin/ endpoint that return non-image content types such as text/plain or application/xml.
  • Baseline the set of skin resource paths served by the deployment and alert on requests that resolve outside that set.

Monitoring Recommendations

  • Enable verbose request-path logging on the Jetty connector, including the original URI before decoding.
  • Forward web-tier logs to a central analytics platform for path-traversal pattern matching across the fleet.
  • Alert on repeated requests to /skin/ from a single source IP within short intervals, which suggests file enumeration.

How to Mitigate CVE-2026-34151

Immediate Actions Required

  • Upgrade XWiki Platform to version 17.10.5 or 18.2.0 as soon as feasible.
  • If upgrade is not immediate, downgrade Jetty to a version prior to 12 or migrate to Tomcat, which is not affected.
  • Rotate any secrets stored in WEB-INF/xwiki.cfg, xwiki.properties, and related configuration files that may have been exposed.
  • Review access logs since Jetty 12 deployment for prior exploitation attempts targeting the /skin/ endpoint.

Patch Information

The issue is fixed in XWiki Platform releases 17.10.5 and 18.2.0. The fix replaces filesystem-based path resolution in AbstractResourceSkin with Environment.getResourceAsStream(String, String), which constrains lookups to the expected resource prefix. Additional context is available in the GitHub Security Advisory GHSA-qj4x-9g63-25g6 and tickets XCOMMONS-3594 and XWIKI-24075.

Workarounds

  • Deploy XWiki on Apache Tomcat or on Jetty versions earlier than 12 until the platform can be patched.
  • Place a reverse proxy in front of XWiki that rejects request URIs containing %25 followed by encoded dot sequences.
  • Restrict filesystem permissions for the Jetty process user so only required resources are readable, limiting blast radius.
bash
# Example reverse-proxy filter (NGINX) rejecting double-encoded traversal on /skin/
location /skin/ {
    if ($request_uri ~* "(%25%32%65|%252e|%252E){2}") {
        return 400;
    }
    proxy_pass http://xwiki_backend;
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.