External risk intelligence

XWiki OIDC User Impersonation via Token Creation

CVE advisorySeverity: CRITICAL (CVSS 9.2)

CVE-2025-49594

XWiki is a web-based collaboration platform that is frequently deployed as an internet-facing or externally accessible application. Because this vulnerability involves the OpenID Connect (OIDC) authentication mechanism, which is often exposed to manage user sessions and login flows for web-accessible services, it is highly likely that this attack surface is reachable in common deployments.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability exists in XWiki's OpenID Connect tools that could allow unauthorized users to authenticate as other users if token authentication is enabled. This is because the system incorrectly allows the creation of authentication tokens from user profile data that is accessible to users with basic viewing permissions.

  • Allows unauthorized access to user accounts.
  • Impacts login processes and user data security.
  • Confirm relevance and exposure of affected systems.

Attack Path

How an attacker could exploit the issue

An attacker could leverage this vulnerability by first gaining the ability to view user profiles. With this access, they can create an authentication token for any user, which, if the system allows token authentication, permits the attacker to log in as that user. This could lead to unauthorized access and control over user accounts.

  • Requires VIEW access to user profiles.
  • Attacker creates an authentication token.
  • Leads to unauthorized user authentication.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, any user with VIEW access to a profile could potentially impersonate another user if token authentication is enabled. This could expose service behavior or sensitive information if the instance is configured to allow token authentication and user profiles are viewable by the attacker.

  • User profile data could be exposed.
  • Via token creation for any user.
  • Unauthorized access to user accounts.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in XWiki's OpenID Connect (OIDC) implementation requires immediate attention from teams managing authentication and application security. The first practical step is to identify all XWiki instances using the affected OIDC module, confirm their exposure and business criticality, and then locate the specific application or platform owners responsible for remediation. Planning for updates or implementing the workaround should be prioritized based on this risk assessment.

  • App/Platform owners should investigate.
  • Verify token authentication reachability.
  • Disable token authentication or update.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is XWiki OIDC and why is it used?

XWiki is a modular, web-based collaboration platform. The OIDC (OpenID Connect) module is an extension that allows XWiki to integrate with external identity providers, enabling users to log in or manage their sessions using standardized authentication protocols. It essentially acts as a bridge between the collaborative environment and centralized user management systems.

What does CWE-285 mean for CVE-2025-49594?

CWE-285 refers to Improper Authorization. In the context of CVE-2025-49594, it means the software fails to properly check if a user has the correct permissions before performing a sensitive action. Specifically, the system incorrectly permits users to generate authentication tokens for other accounts based on profile data that should have been restricted, essentially allowing a user to bypass standard identity verification.

How does an attacker trigger this vulnerability?

An attacker needs to be able to view user profiles on the XWiki instance to initiate the token creation process. The vulnerability is not triggered if token authentication is disabled, as the generated token would have no mechanism to authorize access. It also requires the system to be configured specifically to accept these tokens for authentication.

Is my XWiki instance at risk?

According to Halo Surface Signal, this vulnerability is likely to be reachable because XWiki is frequently deployed as an internet-facing application. Because the bug affects the authentication mechanism used for web-accessible services, any instance that is reachable from the internet and has token authentication enabled faces a higher risk of being targeted by unauthorized users.

What is the recommended first step to secure my instance?

The most immediate and practical step is to verify if your XWiki instance has token authentication enabled, as this is a core requirement for the vulnerability to be exploited. If it is enabled, consider disabling this feature as a temporary workaround until you can apply the official patch in version 2.18.2, which resolves the flaw in the OIDC module.

References