GHSA-qrvh-r3f2-9h4r
CRITICALCVE-2026-33137POST /wikis/{wikiName} executes a XAR import without performing any authentication or authorization checks, allowing an unauthenticated attacker to create or update documents in the target wiki
- Affected
- >= 15.10.6, < 16.10.17
- Fixed in
- 16.10.17
- Weakness
- CWE-862
- Published
- 2026-05-26
- Source
- github