CVE-2026-92776

Summary

Wiki.js through 2.5.314 fails to require path separators when matching START and END page rules, allowing attackers to access pages sharing a prefix with authorized folders. Users granted access to a folder can read and modify unrelated pages with matching prefixes, bypassing intended access controls.

Affected Software

VendorProductVersion RangeStatus
requarksWiki.js0 <= 2.5.314affected

Weaknesses

  • CWE-863: Incorrect Authorization

References