Vulnerability record · CVE-2023-36469 · published 29 June 2023
CVE-2023-36469: XWiki Platform script macro injection in notification settings allows RCE
Xwiki · Xwiki
XWiki Platform lets any user who can edit their own profile and notification settings inject script macros, including Groovy and Python, through the notification RSS service. Because those macros execute server-side, a low-privileged user can run arbitrary code and read or write all wiki contents. The flaw is patched in XWiki 14.10.6 and 15.2RC1.
Description
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who can edit their own user profile and notification settings can execute arbitrary script macros including Groovy and Python macros that allow remote code execution including unrestricted read and write access to all wiki contents. This has been patched in XWiki 14.10.6 and 15.2RC1. Users are advised to update. As a workaround the main security fix can be manually applied by patching the affected document `XWiki.Notifications.Code.NotificationRSSService`. This will break the link to the differences, though as this requires additional changes to Velocity templates as shown in the patch. While the default template is available in the instance and can be easily patched, the template for mentions is contained in a `.jar`-file and thus cannot be fixed without replacing that jar.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with low-privileged network access, full confidentiality, integrity and availability impact, and very high EPSS despite no KEV listing.
What it is
XWiki Platform lets any user who can edit their own profile and notification settings inject script macros, including Groovy and Python, through the notification RSS service. Because those macros execute server-side, a low-privileged user can run arbitrary code and read or write all wiki contents. The flaw is patched in XWiki 14.10.6 and 15.2RC1.
Impact
An authenticated low-privileged user gains remote code execution on the XWiki server, with unrestricted read and write access to all wiki contents. This effectively escalates a normal account to full control over the platform and its data.
Attack surface
Reached over the network through the notification settings and RSS service of XWiki; the CVSS vector shows PR:L and UI:N, so a low-privileged authenticated account is required but no victim interaction is needed.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high at 0.82032 (99.6th percentile) and the vendor advisory and Jira references are tagged Exploit, indicating public exploit detail exists.
What to do
- Upgrade to XWiki 14.10.6 or 15.2RC1 (or later) as the primary fix.
- If immediate upgrade is not possible, manually apply the patch to the XWiki.Notifications.Code.NotificationRSSService document as described in the advisory.
- Note that the workaround breaks the differences link and that the mentions template lives in a .jar, so it cannot be fixed without replacing that jar; plan the full upgrade.
- Restrict who can edit profiles and notification settings until patched, and review accounts with those rights.
- Monitor XWiki logs and content changes for unexpected Groovy or Python macro execution.
Detection
- Search XWiki documents and notification settings for injected Groovy or Python macro syntax.
- Alert on unexpected server-side script execution or child processes spawned by the XWiki application.
- Review changes to XWiki.Notifications.Code.NotificationRSSService and related Velocity templates for unauthorized edits.
- Monitor for outbound connections or file writes from the XWiki host consistent with post-exploitation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-36469 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-36469), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.