Description
Wiki.js through 2.5.314 fails to require path separators when matching START and END page rules, allowing attackers to access pages sharing a prefix with authorized folders. Users granted access to a folder can read and modify unrelated pages with matching prefixes, bypassing intended access controls.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Wed, 16 Sep 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Wiki.js through 2.5.314 fails to require path separators when matching START and END page rules, allowing attackers to access pages sharing a prefix with authorized folders. Users granted access to a folder can read and modify unrelated pages with matching prefixes, bypassing intended access controls. | |
| Title | Wiki.js through 2.5.314 Path Prefix Matching Authorization Bypass | |
| First Time appeared |
Requarks
Requarks wiki.js |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:requarks:wiki.js:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Requarks
Requarks wiki.js |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-16T20:32:36.130Z
Reserved: 2026-09-16T19:15:40.413Z
Link: CVE-2026-92776
No data.
Status : Received
Published: 2026-09-16T21:17:26.547
Modified: 2026-09-16T21:17:26.547
Link: CVE-2026-92776
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-863
Incorrect Authorization