CVE-2025-49594 - CVE House
Back to Database
Status published Critical CVE-2025-49594

XWiki OIDC Authenticator vulnerable to creation of token for any user with just `view` right

Vulnerability Description

XWiki OIDC has various tools to manipulate OpenID Connect protocol in XWiki. Starting in version 2.17.1 and prior to version 2.18.2, anyone with VIEW access to a user profile can create a token for that user. If that XWiki instance is configured to allow token authentication, it allows authentication with any user (since users are very commonly viewable, at least to other registered users). Version 2.18.2 contains a patch. As a workaround, disable token access.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-49594

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

xwiki-contrib

View all reports →

Affected Software

oidc
Vulnerable Versions:
>= 2.17.1, < 2.18.2

Timeline

Official Publish: October 6th, 2025
Last Modified: October 23rd, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)