Access Control Vulnerability in Wiki.js by Requarks
CVE-2026-92776
Key Information:
Badges
What is CVE-2026-92776?
Wiki.js versions up to 2.5.314 exhibit a flaw in the authorization mechanism that fails to enforce strict path separation when applying START and END page rules. This oversight permits attackers to access and modify files that share similar prefixes with permitted folders, thereby circumventing access controls meant to protect sensitive information. Users misconfigured with such permissions may inadvertently expose unrelated pages, compromising the integrity and confidentiality of the application.
Affected Version(s)
Wiki.js 0 <= 2.5.314
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
