rootpwn

high · CVSS v3 8.1 · CVSS v4 8.6

CVE-2026-92776

Wiki.js versions up to 2.5.314 contain an access control bypass due to insufficient path separator requirements in START and END page rule m

Overview

Wiki.js versions up to 2.5.314 contain an access control bypass due to insufficient path separator requirements in START and END page rule matching. This flaw allows users authorized to view or edit a specific folder path to improperly access or alter unrelated pages sharing the same prefix.

Description

Wiki.js through 2.5.314 fails to require path separators when matching START and END page rules, allowing attackers to access pages sharing a prefix with authorized folders. Users granted access to a folder can read and modify unrelated pages with matching prefixes, bypassing intended access controls.

Impact

Authenticated users with restricted folder access can gain unauthorized read and write privileges over adjacent wiki pages sharing a prefix, leading to potential loss of confidentiality and integrity.

Remediation

Update Wiki.js to a patched release newer than 2.5.314 as soon as vendor fixes are applied. As a temporary mitigation, audit folder naming structures and page rules to minimize prefix overlaps between sensitive and standard folders.

Risk context

Rated as High severity (CVSS v3: 8.1, CVSS v4: 8.6), this issue creates a significant authorization flaw in multi-user environments relying on path-based rule enforcement.

Affected products

  • Requarks Wiki.js

Scores

Severity
high
CVSS v2
8.5
CVSS v3
8.1
CVSS v4
8.6
EPSS

Wiki.js Access Control Authorization Bypass Path Normalization CVE-2026-92776

← All CVEs