External risk intelligence

XWiki Platform Configuration File Access Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2025-55748

XWiki is a web-based collaboration platform commonly deployed as a public-facing web application. The vulnerability exists within the web interface endpoints (jsx and sx), which are exposed to network traffic by design in standard web server deployments, making the vulnerable paths reachable from the internet.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A security issue has been identified in the XWiki Platform, affecting how configuration files are accessed. This vulnerability could allow unauthorized individuals to read sensitive configuration details. The primary concern is to determine if your organization utilizes this platform and is exposed.

  • Configuration files are readable via web requests.
  • Understand if XWiki is in use.
  • Assess exposure and confirm relevance.

Attack Path

How an attacker could exploit the issue

An attacker can access sensitive configuration files by crafting a special URL to exploit a weakness in how XWiki Platform handles requests for certain resources. This could allow them to read configuration details that might reveal further system information.

  • Attacker reaches vulnerable endpoints via URL.
  • Vulnerable component: Web interface resource access.
  • Risk: Sensitive configuration files exposed.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, this vulnerability could allow unauthorized parties to read sensitive configuration files from the XWiki Platform. This could occur when an attacker accesses specific API endpoints that do not properly validate resource paths, potentially exposing details about the wiki's setup.

  • Configuration files could be exposed.
  • Unauthenticated access to specific endpoints.
  • Exposure of system setup details.

Operational Fix

Recommended remediation, mitigation, and detection steps

The XWiki Platform's configuration files are accessible via specific web endpoints, posing a critical risk. Application owners or platform teams are likely responsible for managing XWiki instances. The first practical step is to identify all XWiki deployments, determine their network exposure and business criticality, and then plan remediation based on these findings.

  • Application and platform teams own this issue.
  • Verify XWiki instance reachability and criticality.
  • Plan remediation, coordinate with vendors.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the XWiki Platform and what is it used for?

XWiki Platform is a versatile, open-source software used to build collaborative wiki applications and business tools. It provides a runtime environment that allows organizations to create, manage, and host web-based content and structured applications within a central system.

What is the weakness behind CVE-2025-55748?

This vulnerability is classified as CWE-23, or Relative Path Traversal. It occurs because the software fails to properly sanitize file paths in certain web requests. Consequently, an attacker can manipulate input to navigate outside intended directories and access configuration files stored on the server.

How can an attacker trigger this vulnerability?

An attacker can exploit this by sending a specially crafted HTTP request to specific 'jsx' or 'sx' endpoints on the XWiki server. The request includes a path that points to sensitive configuration files like 'xwiki.cfg'. The bug is triggered solely through these web requests; it cannot be triggered if the affected endpoints are completely disabled or inaccessible via the network.

Why should I care about this vulnerability?

According to Halo Surface Signal, XWiki is commonly deployed as a public-facing application, meaning your instance is likely reachable from the internet. Because this issue allows unauthenticated access to sensitive system files, any XWiki server exposed to the network is at risk of information disclosure.

How do I respond to this vulnerability?

Begin by auditing your environment to identify all active XWiki deployments and confirming their specific version numbers. Once you have an inventory, prioritize patching instances that are internet-facing or contain critical business data. Verify your current version and coordinate with your team to update to a non-vulnerable release.

References