CVE-2025-49594

CRITICAL

XWiki OIDC 2.17.1-2.18.1 - Improper Authorization via User Profile Token Creation

Title source: llm
STIX 2.1

Description

XWiki OIDC has various tools to manipulate OpenID Connect protocol in XWiki. Starting in version 2.17.1 and prior to version 2.18.2, anyone with VIEW access to a user profile can create a token for that user. If that XWiki instance is configured to allow token authentication, it allows authentication with any user (since users are very commonly viewable, at least to other registered users). Version 2.18.2 contains a patch. As a workaround, disable token access.

Scores

CVSS v4 9.2
EPSS 0.0054
EPSS Percentile 41.2%
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-285
Status published
Products (2)
org.xwiki.contrib.oidc/oidc-authenticator 2.17.1 - 2.18.2Maven
xwiki-contrib/oidc >= 2.17.1, < 2.18.2
Published Oct 06, 2025
Tracked Since Feb 18, 2026