CVE-2026-48048
published 2026-08-10CVE-2026-48048: XWiki Platform is a generic wiki platform. XWiki discovered that the patch for GHSA-5cf8-vrr8-8hjm was insufficient. Starting with version 6.2.1 and prior to…
PriorityP348high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.36%
29.9th percentile
XWiki Platform is a generic wiki platform. XWiki discovered that the patch for GHSA-5cf8-vrr8-8hjm was insufficient. Starting with version 6.2.1 and prior to versions 18.0.0RC1, 17.10.13, 17.4.9 and 16.10.17, with slightly modified parameters to the `LiveTableResults`, it is still possible to discover password hashes one bit at a time, so with 768 requests, the full password salt and hash can be retrieved of a user. The check for password (and email properties) has been adjusted in XWiki 18.0.0RC1, 17.10.13, 17.4.9 and 16.10.17. As a workaround, the patch can be applied manually to the wiki page `XWiki.LiveTableResultsMacros`.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| xwiki | xwiki-platform | — | — |
| xwiki | xwiki-platform | — | — |
| xwiki | xwiki-platform | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
XWiki prior 16.10.17/17.4.9/17.10.13/18.0.0RC1 LiveTableResults weak password hash
vuldb·2026-09-19·CVSS 7.5
CVE-2026-48048 [HIGH] XWiki prior 16.10.17/17.4.9/17.10.13/18.0.0RC1 LiveTableResults weak password hash
A vulnerability has been found in XWiki and classified as problematic. This impacts an unknown function of the component LiveTableResults. The manipulation leads to password hash with insufficient computational effort.
This vulnerability is listed as CVE-2026-48048. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.
GHSA
XWiki Platform's Livetable results still allow reconstructing password hashes using 768 requests
ghsa·2026-05-26
CVE-2026-48048 [HIGH] CWE-359 XWiki Platform's Livetable results still allow reconstructing password hashes using 768 requests
XWiki Platform's Livetable results still allow reconstructing password hashes using 768 requests
### Impact
XWiki discovered that the patch for GHSA-5cf8-vrr8-8hjm was insufficient and with slightly modified parameters to the `LiveTableResults`, it is still possible to discover password hashes one bit at a time, so with 768 requests, the full password salt and hash can be retrieved of a user.
### Patches
The check for password (and email properties) has been adjusted in XWiki 18.0.0RC1, 17.10.13, 17.4.9 and 16.10.17.
### Workarounds
The [patch](https://github.com/xwiki/xwiki-platform/commit/c4442716b02ffcdaa9d5e703b1db6203e36456fa#diff-5a739e5865b1f1ad9d79b724791be51b0095a0170cc078911c940478b13b949a) can be applied manually to the wiki page `XWiki.LiveTableResultsMacros`.
### Resources
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-10
Published