← Vulnerability feed

Vulnerability record · CVE-2023-48241 · published 20 November 2023

CVE-2023-48241: XWiki Solr search API authorization bypass exposes all wiki documents

Xwiki · Xwiki

XWiki Platform's Solr-based search suggestion provider, which also serves as a generic JavaScript API for search results, exposes the content of all documents across all wikis to anyone with access to it, and it is public by default. The normal right check can be bypassed by explicitly requesting Solr fields that omit the data used for the authorization check, so the flaw is an improper authorization issue rather than a memory or injection bug.

7.5 CVSS 3.1 High EPSS 73% · top 0.6% CWE-285 · Improper authorization
7.5CVSS 3.1 base score
73%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

XWiki Platform is a generic wiki platform. Starting in version 6.3-milestone-2 and prior to versions 14.10.15, 15.5.1, and 15.6RC1, the Solr-based search suggestion provider that also duplicates as generic JavaScript API for search results in XWiki exposes the content of all documents of all wikis to anybody who has access to it, by default it is public. This exposes all information stored in the wiki (but not some protected information like password hashes). While there is a right check normally, the right check can be circumvented by explicitly requesting fields from Solr that don't include the data for the right check. This has been fixed in XWiki 15.6RC1, 15.5.1 and 14.10.15 by not listing documents whose rights cannot be checked. No known workarounds are available.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityCVSS 7.5 with no authentication or interaction required and a very high EPSS score, though no KEV listing or documented exploitation yet.

What it is

XWiki Platform's Solr-based search suggestion provider, which also serves as a generic JavaScript API for search results, exposes the content of all documents across all wikis to anyone with access to it, and it is public by default. The normal right check can be bypassed by explicitly requesting Solr fields that omit the data used for the authorization check, so the flaw is an improper authorization issue rather than a memory or injection bug.

Impact

An unauthenticated attacker can read the content of every document in every wiki, including content that should be restricted by rights. Protected material such as password hashes is not exposed, but the bulk of stored wiki information is.

Attack surface

Reachable over the network through the Solr search suggestion provider / JavaScript search API, which is public by default. No authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

Not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high at 0.7282 (99.4th percentile), indicating substantial predicted exploitation activity. References are limited to the patch, vendor advisory and issue tracker, with no public exploit tag.

What to do

  • Upgrade to XWiki 15.6RC1, 15.5.1 or 14.10.15, which fix the issue by not listing documents whose rights cannot be checked.
  • If immediate upgrade is not possible, restrict network access to the Solr search suggestion provider and the JavaScript search API to trusted users only.
  • Review wiki content for sensitive data that may have been exposed and rotate any credentials or secrets stored in documents.
  • Monitor vendor advisory GHSA-7fqr-97j7-jgf4 and XWIKI-21138 for any updated guidance, since no workaround is documented.

Detection

  • Audit Solr search API requests for explicit field lists that omit the fields used for rights checking.
  • Monitor for unauthenticated or anomalous access to the search suggestion endpoint from unexpected source IPs.
  • Review web and application logs for bulk document retrieval patterns consistent with enumerating all wiki content.
  • Alert on access to the search API from accounts or networks that do not normally use search functionality.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-48241 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-24893XWiki SolrSearch unauthenticated remote code executionXWiki Platform's SolrSearch endpoint evaluates user-supplied search text as Groovy code, allowing arbitrary remote code execution. The flaw is reacha…KEVEPSS 100%analysed9.9CVE-2023-27479Xwiki injection vulnerabilityXWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with view righ…EPSS 1.1%9.8CVE-2024-31996Xwiki code injection vulnerabilityXWiki Platform is a generic wiki platform. Starting in version 3.0.1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, the HTML escaping of esca…EPSS 2.1%9.8CVE-2024-31982Xwiki code injection vulnerabilityXWiki Platform is a generic wiki platform. Starting in version 2.4-milestone-1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, XWiki's databas…EPSS 35%9.8CVE-2024-21650XWiki user registration RCE via name fieldsXWiki Platform is vulnerable to remote code execution through its guest user registration feature. An attacker can inject malicious payloads into the…EPSS 93%analysed9.8CVE-2023-46731XWiki Platform unescaped URL parameter allows remote code executionXWiki Platform fails to properly escape the section URL parameter used when displaying administration sections, allowing injection of code such as Gr…EPSS 89%analysed9.8CVE-2023-26477XWiki Platform unauthenticated code injection via newThemeName parameterXWiki Platform versions from 6.3-rc-1 and 6.2.4 onward allow injection of arbitrary wiki syntax, including Groovy, Python and Velocity script macros,…EPSS 75%analysed9.8CVE-2022-29161Xwiki broken cryptographic algorithm vulnerabilityXWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The XWiki Crypto API will generate X509 cert…EPSS 0.41%

Source: NIST National Vulnerability Database (record CVE-2023-48241), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.