CVE-2025-49594

CRITICAL

Org.xwiki.contrib.oidc Oidc-authenticator - Improper Authorization

Title source: rule
STIX 2.1

Description

XWiki OIDC has various tools to manipulate OpenID Connect protocol in XWiki. Starting in version 2.17.1 and prior to version 2.18.2, anyone with VIEW access to a user profile can create a token for that user. If that XWiki instance is configured to allow token authentication, it allows authentication with any user (since users are very commonly viewable, at least to other registered users). Version 2.18.2 contains a patch. As a workaround, disable token access.

Scores

CVSS v4 9.2
EPSS 0.0016
EPSS Percentile 37.2%
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-285
Status published
Products (2)
org.xwiki.contrib.oidc/oidc-authenticator 2.17.1 - 2.18.2Maven
xwiki-contrib/oidc >= 2.17.1, < 2.18.2
Published Oct 06, 2025
Tracked Since Feb 18, 2026