PT-2026-94054 · Requarks+1 · Wiki.Js+1

·

CVE-2026-92776

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Wiki.js versions prior to 2.5.315
Description An issue exists where the software fails to require path separators when matching START and END page rules. This allows users who have been granted access to a specific folder to read and modify unrelated pages that share a common prefix with those authorized folders, effectively bypassing intended access controls.
Recommendations Update to version 2.5.315 or later.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92776

Affected Products

Wiki.Js
Wiki