CVE-2026-26000 | xwiki xwiki-platform up to 16.10.12/17.4.5/17.8.x CSS ui layer (GHSA-74rh-c5rh-88vg / WID-SEC-2026-0412)
A vulnerability was found in xwiki xwiki-platform up to 16.10.12/17.4.5/17.8.x. It has been rated as problematic. This vulnerability affects unknown code of the component CSS Handler. The manipulation leads to improper restriction of rendered ui layers.
This vulnerability is documented as CVE-2026-26000. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.