Impact
DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote attacker to create an account via the register function in inc/auth.php. The supplier asserts that this behavior is intentional when the product is configured for self‑registration, which is a non‑default feature, and that no configuration migration can enable self‑registration without the administrator’s knowledge. For installations that have the self‑registration feature enabled, the flaw permits unauthorized account creation (CWE‑640) and constitutes an authentication bypass (CWE‑306).
Affected Systems
The affected software is DokuWiki version 2025-05-14b "Librarian" 56.2. Any installation of this release that has the register feature enabled is vulnerable; the flaw only applies when self‑registration is allowed, a configuration that is not enabled by default.
Risk and Exploitability
Based on the provided data, the attack vector is remote network access to the register endpoint. The EPSS score of <1% indicates a very low exploitation probability, while the CVSS score of 9.8 reflects a critical severity. The vulnerability is not listed in the CISA KEV catalog, indicating that no known exploits have been reported yet.
OpenCVE Enrichment