Description
Wiki.js through 2.5.314 fails to require path separators when matching START and END page rules, allowing attackers to access pages sharing a prefix with authorized folders. Users granted access to a folder can read and modify unrelated pages with matching prefixes, bypassing intended access controls.
Published: 2026-09-16
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access to pages
Action: Immediate Patch
AI Analysis

Impact

Wiki.js through 2.5.314 does not enforce path separators when evaluating START and END page rules, allowing a user granted access to a folder to view or modify any page that shares that folder’s literal prefix. The result is an authorization bypass that gives attackers unwarranted confidentiality and integrity access to unrelated pages, potentially enabling data exfiltration or malicious content injection.

Affected Systems

The vulnerability affects Requarks Wiki.js, versions up to and including 2.5.314. Users deploying any of these releases are at risk unless mitigated or updated.

Risk and Exploitability

The CVSS score of 8.6 signals high severity. The EPSS score is less than 1%, indicating a low current exploitation probability, and the flaw is not listed in the CISA KEV catalog. Attackers may exploit the flaw by sending crafted requests to a Wiki.js instance that they can reach; while the description does not specify an authentication requirement, the bypass occurs regardless of the specific access level assigned to the user’s folder, suggesting that an authenticated user or an attacker with network access to the site can benefit from the flaw.

Generated by OpenCVE AI on September 18, 2026 at 06:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Wiki.js version 2.5.315 or later where the path separator check is implemented.
  • If an upgrade is not immediately possible, patch the core authentication file (core/auth.js) to enforce a strict separator check between path segments before authorizing access.
  • Implement network or application‑level restrictions so that only trusted hosts can reach the Wiki.js instance, and enable or enforce full authentication to limit exposure until a permanent fix is applied.

Generated by OpenCVE AI on September 18, 2026 at 06:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description Wiki.js through 2.5.314 fails to require path separators when matching START and END page rules, allowing attackers to access pages sharing a prefix with authorized folders. Users granted access to a folder can read and modify unrelated pages with matching prefixes, bypassing intended access controls.
Title Wiki.js through 2.5.314 Path Prefix Matching Authorization Bypass
First Time appeared Requarks
Requarks wiki.js
Weaknesses CWE-863
CPEs cpe:2.3:a:requarks:wiki.js:*:*:*:*:*:*:*:*
Vendors & Products Requarks
Requarks wiki.js
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Requarks Wiki.js
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-18T18:32:42.162Z

Reserved: 2026-09-16T19:15:40.413Z

Link: CVE-2026-92776

cve-icon Vulnrichment

Updated: 2026-09-18T18:32:26.265Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T21:17:26.547

Modified: 2026-09-24T21:08:22.573

Link: CVE-2026-92776

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T17:30:11Z

Weaknesses