CVE-2024-55879

CRITICAL

XWiki 2.3-15.10.8 and 16.0.0-16.2.0 - Authenticated Remote Code Execution via ConfigurableClass Instance Addition

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-55879. PoCs published by dbwlsdnr95.

AI-analyzed exploit summary This repository contains a functional simulation of CVE-2024-55879, an RCE vulnerability in XWiki Platform, using Spring Boot and Groovy to demonstrate unsafe script execution. It includes a Dockerized environment, exploit simulation via curl, and detailed testing documentation.

Description

XWiki Platform is a generic wiki platform. Starting in version 2.3 and prior to versions 15.10.9, 16.3.0, any user with script rights can perform arbitrary remote code execution by adding instances of `XWiki.ConfigurableClass` to any page. This compromises the confidentiality, integrity and availability of the whole XWiki installation. This has been patched in XWiki 15.10.9 and 16.3.0. No known workarounds are available except upgrading.

Exploits (1)

nomisec WORKING POC
by dbwlsdnr95 · poc
https://github.com/dbwlsdnr95/CVE-2024-55879

This repository contains a functional simulation of CVE-2024-55879, an RCE vulnerability in XWiki Platform, using Spring Boot and Groovy to demonstrate unsafe script execution. It includes a Dockerized environment, exploit simulation via curl, and detailed testing documentation.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: XWiki Platform 15.10.5 and below
Auth required
Prerequisites: Docker · XWiki admin access · Groovy script execution context
devstral-2 · analyzed Feb 26, 2026 Full analysis →

Scores

CVSS v3 9.1
EPSS 0.2002
EPSS Percentile 95.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-862
Status published
Products (3)
org.xwiki.platform/xwiki-platform-administration-ui 2.3 - 15.10.9Maven
xwiki/xwiki 16.0.0 - 16.3.0
xwiki/xwiki 2.3 - 15.10.9
Published Dec 12, 2024
Tracked Since Feb 18, 2026