Vulnerability record · CVE-2023-35166 · published 20 June 2023
CVE-2023-35166: XWiki Platform authorization flaw allows wiki content execution as TipsPanel author
Xwiki · Xwiki
XWiki Platform has an incorrect authorization flaw (CWE-863) where a user can execute arbitrary wiki content with the rights of the TipsPanel author by creating a tip UI extension. This matters because it lets a low-privileged user escalate to the privileges of the TipsPanel author and run content they should not be able to run. It is patched in XWiki 15.1-rc-1 and 14.10.5.
Description
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to execute any wiki content with the right of the TipsPanel author by creating a tip UI extension. This has been patched in XWiki 15.1-rc-1 and 14.10.5.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with low-privileged network access and high EPSS, but no confirmed in-the-wild exploitation or KEV listing.
What it is
XWiki Platform has an incorrect authorization flaw (CWE-863) where a user can execute arbitrary wiki content with the rights of the TipsPanel author by creating a tip UI extension. This matters because it lets a low-privileged user escalate to the privileges of the TipsPanel author and run content they should not be able to run. It is patched in XWiki 15.1-rc-1 and 14.10.5.
Impact
An attacker with a low-privileged account gains the ability to execute wiki content under the TipsPanel author's rights, which can lead to unauthorized actions and data exposure within the wiki. The CVSS vector indicates high confidentiality, integrity, and availability impact.
Attack surface
The flaw is reachable over the network via the wiki UI extension mechanism, requiring a low-privileged authenticated account and no user interaction. The CVSS vector is AV:N/AC:L/PR:L/UI:N.
Exploitation
No CISA KEV listing is present, but EPSS is 0.62172 (99.1st percentile) and a vendor Jira reference is tagged Exploit, indicating public exploit information exists.
What to do
- Upgrade XWiki to 15.1-rc-1 or 14.10.5 or later.
- If immediate upgrade is not possible, restrict who can create tip UI extensions and review existing tip extensions for unauthorized content.
- Limit the privileges of the TipsPanel author account and audit accounts with elevated wiki content execution rights.
- Monitor vendor advisories and the referenced patch commit for backport guidance on older branches.
Detection
- Audit creation and modification of tip UI extensions in XWiki and alert on unexpected authors.
- Review wiki content execution logs for actions performed under the TipsPanel author account that do not match normal administrative activity.
- Search for the referenced Jira issue XWIKI-20281 and patch commit in change-management records to confirm remediation status.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-35166 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-35166), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.