CVE-2024-31996
Java vulnerability analysis and mitigation

Overview

CVE-2024-31996 affects XWiki Platform, a generic wiki platform. The vulnerability exists in versions starting from 3.0.1 and prior to versions 14.10.19, 15.5.4, and 15.10-rc-1, where the HTML escaping tool used in XWiki fails to escape the '{' character, enabling XWiki syntax injection and potential remote code execution (GitHub Advisory, NVD).

Technical details

The vulnerability stems from a flaw in the HTML escaping functionality where the '{' character is not properly escaped by the $escapetool.html method. This oversight allows for XWiki syntax injection in certain contexts. The vulnerability has received a CVSS v3.1 base score of 10.0 CRITICAL (Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) from GitHub, and 9.8 CRITICAL from NVD. The issue is classified as CWE-94 (Improper Control of Generation of Code) and CWE-95 (Improper Neutralization of Directives in Dynamically Evaluated Code) (GitHub Advisory, NVD).

Impact

The vulnerability allows attackers to perform remote code execution through XWiki syntax injection. In a standard XWiki installation, the document 'Panels.PanelLayoutUpdate' is known to be vulnerable, and any extension could potentially expose this vulnerability. The issue enables privilege escalation from view rights to programming rights, allowing execution of arbitrary Velocity or Groovy code (XWIKI Issue).

Exploitability

The vulnerability can be exploited by accessing specific URLs with crafted parameters. A proof of concept exists where an attacker can execute arbitrary code by accessing the PanelLayoutUpdate panel with specific parameters, even as a guest or logged-in user without wiki admin rights (XWIKI Issue).

Mitigation and workarounds

The vulnerability has been fixed in XWiki versions 14.10.19, 15.5.5, and 15.9 RC1. For those unable to upgrade immediately, a workaround exists by replacing $escapetool.html with $escapetool.xml in XWiki documents. In standard installations, patching the Panels.PanelLayoutUpdate document can mitigate the vulnerability, though any extension could potentially need similar patching (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-76904CRITICAL9.8
  • Java logoJava
  • org.geotools.jdbc:gt-jdbc-postgis
NoYesAug 21, 2026
GHSA-mqjf-5f49-2fjhCRITICAL9.8
  • Java logoJava
  • org.geotools:gt-jdbc-postgis
NoYesAug 21, 2026
CVE-2026-61827HIGH8.7
  • Java logoJava
  • io.netty.incubator:netty-incubator-codec-bhttp
NoYesAug 20, 2026
CVE-2026-63202HIGH7.5
  • Java logoJava
  • io.netty.incubator:netty-incubator-codec-bhttp
NoYesAug 20, 2026
CVE-2026-63124HIGH7.5
  • Java logoJava
  • io.netty.incubator:netty-incubator-codec-bhttp
NoYesAug 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management