CVE-2025-29924 | xwiki-platform up to 15.10.13/16.4.5/16.9.x REST API privileges management (GHSA-gq32-758c-3wm3)
A vulnerability classified as critical has been found in xwiki-platform up to 15.10.13/16.4.5/16.9.x. This affects an unknown part of the component REST API. The manipulation leads to improper privilege management.
This vulnerability is uniquely identified as CVE-2025-29924. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.