Description
Wiki.js through 2.5.314 omits page tags from authorization checks in multiple GraphQL resolvers, allowing tag-based access restrictions to be bypassed. Attackers can query the list, tree, tags, searchTags, and links resolvers to retrieve restricted page metadata including titles, descriptions, paths, and tag information without proper authorization.
Published: 2026-09-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authorization Bypass – sensitive page metadata disclosure
Action: Patch Now
AI Analysis

Impact

Wiki.js up to and including version 2.5.314 omits page tags from authorization checks in several GraphQL resolvers. This omission lets an attacker query the list, tree, tags, searchTags, and links endpoints and retrieve metadata—titles, descriptions, paths, and tag information—of pages that should be protected. The vulnerability is a classic authorization bypass (CWE‑863) and can expose confidential content without proper authorization.

Affected Systems

The vulnerability affects the Requarks Wiki.js product, specifically release 2.5.314. No other releases are mentioned in the advisory as impacted.

Risk and Exploitability

The CVSS score of 5.3 classifies the issue as moderate severity, and the EPSS score of less than 1% indicates a low probability of exploitation. The likely attack vector is sending unauthenticated GraphQL queries over HTTP, exploiting the missing tag checks to obtain restricted page metadata. The vulnerability is not listed in the CISA KEV catalog, so no documented exploits exist, but the absence of proper authorization remains a security risk.

Generated by OpenCVE AI on September 17, 2026 at 22:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Wiki.js to the latest release that implements proper tag-based authorization checks in all GraphQL resolvers.
  • Restrict or block unauthenticated GraphQL queries that expose page metadata such as list, tree, tags, searchTags, and links.
  • Review and enforce access controls on tag usage, ensuring that proper authorization checks are in place for all GraphQL resolvers.

Generated by OpenCVE AI on September 17, 2026 at 22:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description Wiki.js through 2.5.314 omits page tags from authorization checks in multiple GraphQL resolvers, allowing tag-based access restrictions to be bypassed. Attackers can query the list, tree, tags, searchTags, and links resolvers to retrieve restricted page metadata including titles, descriptions, paths, and tag information without proper authorization.
Title Wiki.js through 2.5.314 Authorization Bypass via GraphQL Tag Omission
First Time appeared Requarks
Requarks wiki.js
Weaknesses CWE-863
CPEs cpe:2.3:a:requarks:wiki.js:*:*:*:*:*:*:*:*
Vendors & Products Requarks
Requarks wiki.js
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Requarks Wiki.js
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T15:02:15.325Z

Reserved: 2026-09-16T19:15:39.714Z

Link: CVE-2026-92774

cve-icon Vulnrichment

Updated: 2026-09-17T15:02:10.854Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T21:17:26.247

Modified: 2026-09-24T20:47:31.797

Link: CVE-2026-92774

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T23:00:13Z

Weaknesses