Impact
The CVE description indicates that DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote attacker to create an account through the register function in inc/auth.php. The vendor disputes this claim, stating that account creation via registration is the intended behavior when self‑registration is enabled, a non‑default setting, and that no configuration migration scenario could enable self‑registration without the administrator’s knowledge. The vulnerability bypasses authentication checks and permits unauthorized account creation (CWE‑640), representing an authentication bypass (CWE‑306).
Affected Systems
The affected software is DokuWiki version 2025-05-14b 'Librarian' 56.2. Any installation of this release that has the register feature enabled is vulnerable; the flaw only applies when self‑registration is allowed, a configuration that is not enabled by default.
Risk and Exploitability
Based on the provided data, the attack vector is remote network access to the register endpoint. The EPSS score of <1% indicates a very low exploitation probability, while the CVSS score of 9.8 reflects a critical severity. The vulnerability is not listed in the CISA KEV catalog, indicating that no known exploits have been reported yet.
OpenCVE Enrichment