PT-2026-94052 · Requarks+1 · Wiki.Js+1

·

CVE-2026-92774

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Wiki.js versions prior to 2.5.315
Description Authorization checks in multiple GraphQL resolvers omit page tags, which allows the bypass of tag-based access restrictions. An attacker can use the list, tree, tags, searchTags, and links resolvers to retrieve restricted page metadata, such as titles, descriptions, paths, and tag information, without proper authorization.
Recommendations Update to version 2.5.315 or later.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92774

Affected Products

Wiki.Js
Wiki