CVE-2025-46554
Java vulnerability analysis and mitigation

Overview

XWiki, a generic wiki platform, was found to contain a Missing Authorization vulnerability (CVE-2025-46554) that affects versions from 1.8.1 to before 14.10.22, from 15.0-rc-1 to before 15.10.12, from 16.0.0-rc-1 to before 16.4.3, and from 16.5.0-rc-1 to before 16.7.0. The vulnerability was disclosed on April 30, 2025, and has been patched in versions 14.10.22, 15.10.12, 16.4.3, and 16.7.0 (GitHub Advisory).

Technical details

The vulnerability is classified as a Missing Authorization issue (CWE-862) with a CVSS v3.1 base score of 5.3 (Medium). The security flaw allows unauthorized access to attachment metadata in the wiki through the wiki attachment REST endpoint, with no filtering of results based on user rights. This means even unauthenticated users can access this information in a private wiki (GitHub Advisory, NVD).

Impact

The vulnerability enables unauthorized users to access metadata of any attachment in the wiki, including sensitive information such as hierarchy, file names, page naming, and authors. While this does not grant access to the actual attachment contents, it can reveal sensitive information about the wiki's structure and users (XWIKI Issue).

Mitigation and workarounds

The only known mitigation is to upgrade to the patched versions: 14.10.22, 15.10.12, 16.4.3, or 16.7.0. No alternative workarounds are available (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-22244CRITICAL9.1
  • JavaJava
  • org.open-metadata:platform
NoYesJan 07, 2026
CVE-2025-66518HIGH8.8
  • JavaJava
  • org.apache.kyuubi:kyuubi-server_2.12
NoYesJan 05, 2026
CVE-2025-61916HIGH7.9
  • JavaJava
  • io.spinnaker.clouddriver:clouddriver-artifacts
NoYesJan 05, 2026
CVE-2025-68280MEDIUM6.5
  • JavaJava
  • org.apache.sis.core:sis-metadata
NoYesJan 05, 2026
CVE-2025-66560MEDIUM5.9
  • JavaJava
  • io.quarkus:quarkus-rest
NoYesJan 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management