XWiki OIDC has various tools to manipulate OpenID Connect protocol in XWiki. Starting in version 2.17.1 and prior to version 2.18.2, anyone with VIEW access to a user profile can create a token for that user. If that XWiki instance is configured to allow token authentication, it allows authentication with any user (since users are very commonly viewable, at least to other registered users). Version 2.18.2 contains a patch. As a workaround, disable token access.
{
"cwe_ids": [
"CWE-285"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/49xxx/CVE-2025-49594.json",
"cna_assigner": "GitHub_M"
}"2026-08-12T15:13:55Z"
[
{
"id": "CVE-2025-49594-705335ce",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 181.0,
"function_hash": "129946113780309351542741137391691015184"
},
"source": "https://github.com/xwiki-contrib/oidc/commit/d90d717172283aaa96bb5bb44e357f910ae64adb",
"target": {
"function": "gotToClientLogin",
"file": "oidc-test/oidc-test-tests/src/test/it/org/xwiki/oidc/test/OIDCTest.java"
}
},
{
"id": "CVE-2025-49594-8381e2c4",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 1617.0,
"function_hash": "188980292455528951297510936192278477097"
},
"source": "https://github.com/xwiki-contrib/oidc/commit/d90d717172283aaa96bb5bb44e357f910ae64adb",
"target": {
"function": "authenticate",
"file": "oidc-test/oidc-test-tests/src/test/it/org/xwiki/oidc/test/OIDCTest.java"
}
},
{
"id": "CVE-2025-49594-c358f74e",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"241991066023059200211056234269667645337",
"332590395925087921627746333500413674385",
"335638851061567261054746334414547722186"
]
},
"source": "https://github.com/xwiki-contrib/oidc/commit/d90d717172283aaa96bb5bb44e357f910ae64adb",
"target": {
"file": "oidc-test/oidc-test-pageobjects/src/main/java/org/xwiki/contrib/oidc/test/po/OIDCApplicationsUserProfilePage.java"
}
},
{
"id": "CVE-2025-49594-e565227a",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"229528794327524446060903896261905976414",
"139165536846402449262115918778148651038",
"88962898386376036737307147338619854897",
"79147450128081559006842428430061934995",
"197465954177930890294324174118029910444",
"142119685924524377739373484297605504347",
"159369312681646380229415035545432665202",
"37944239998772979222556235683157754608",
"5368919076969964730266111657222800545",
"184837152916194442254233953502163593767",
"237858823074161969043858417201417490760",
"325818077261712919860286418637098457542",
"297279304858854793038754434725386691715",
"177997140429792642100668255333929835728",
"97630744059405324932080733883942495990",
"326463469950490921736858190506923192771",
"28342911674825607708937696878419416935",
"49737827580179370130473111916934261804",
"331693214186501240357396672343118176364",
"292445535845504274564627410826323931220",
"285963409915173775371271592243078756807",
"20211591574812166509456297708813300594",
"275437397108146179701200569362692182583",
"38943569287977992884306614471398302128",
"115784782417022270488302713759489354659",
"332436537174201283614325213576527553927",
"162514276196985102505429502555326481921",
"127337490145415721666026933085541089928",
"111826637977999686880350869331607179235",
"273823186347110169693755587206591458443",
"177642719496994047534821010543039249385"
]
},
"source": "https://github.com/xwiki-contrib/oidc/commit/d90d717172283aaa96bb5bb44e357f910ae64adb",
"target": {
"file": "oidc-test/oidc-test-tests/src/test/it/org/xwiki/oidc/test/OIDCTest.java"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-49594.json"