Privilege Escalation Vulnerability in LeafWiki by Perber
CVE-2026-53527
8.8HIGH
What is CVE-2026-53527?
LeafWiki versions 0.1.0 through 0.10.0 contain a vulnerability that allows authenticated users to escalate their privileges via the user update API. This flaw enables a regular user, such as a 'viewer', to modify their own account role to 'admin'. To safeguard against this vulnerability, it is advised that users upgrade to version 0.10.1 or later. In the interim, operators should consider restricting account creation to trusted individuals and limiting access to the user update API.
Affected Version(s)
leafwiki >= 0.1.0, < 0.10.1
