A privilege escalation vulnerability, identified as CVE-2026-53966 with a CVSS score of 7.1, exists in the XWiki Platform Live Data Live Table Connector. This flaw allows any user who can edit a page to use the connector's edit REST API and change rights on that page, ultimately obtaining script right and executing potentially dangerous scripts or sending unfiltered HTML and JavaScript to the client. The vulnerability affects versions prior to 16.10.17 of the org.xwiki.platform:xwiki-platform-livedata-livetable package, as well as other specific version ranges, including >= 13.4-rc-1, < 16.10.17, >= 17.0.0-rc-1, < 17.4.10, >= 17.5.0-rc-1, < 17.10.4, and >= 18.0.0-rc-1, < 18.1.0-rc-1. This vulnerability has significant business impact as it enables unauthorized users to execute potentially malicious scripts and compromise the security of the system.
We recommend you to update XWiki Platform Live Data Live Table Connector to version 16.10.17, 17.4.10, 17.10.4, or 18.1.0-rc-1.[/subscribe_to_unlock_form]
A privilege escalation vulnerability, identified as CVE-2026-53966 with a CVSS score of 7.1, exists in the XWiki Platform Live Data Live Table Connector. This flaw allows any user who can edit a page to use the connector's edit REST API and change rights on that page, ultimately obtaining script right and executing potentially dangerous scripts or sending unfiltered HTML and JavaScript to the client. The vulnerability affects versions prior to 16.10.17 of the org.xwiki.platform:xwiki-platform-livedata-livetable package, as well as other specific version ranges, including >= 13.4-rc-1, < 16.10.17, >= 17.0.0-rc-1, < 17.4.10, >= 17.5.0-rc-1, < 17.10.4, and >= 18.0.0-rc-1, < 18.1.0-rc-1. This vulnerability has significant business impact as it enables unauthorized users to execute potentially malicious scripts and compromise the security of the system.
We recommend you to update XWiki Platform Live Data Live Table Connector to version 16.10.17, 17.4.10, 17.10.4, or 18.1.0-rc-1.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]