Wiki.js through 2.5.314 omits page tags from authorization checks in multiple GraphQL resolvers, allowing tag-based access restrictions to be bypassed. Attackers can query the list, tree, tags, searchTags, and links resolvers to retrieve restricted page metadata including titles, descriptions, paths, and tag information without proper authorization.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 16 Sep 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Wiki.js through 2.5.314 omits page tags from authorization checks in multiple GraphQL resolvers, allowing tag-based access restrictions to be bypassed. Attackers can query the list, tree, tags, searchTags, and links resolvers to retrieve restricted page metadata including titles, descriptions, paths, and tag information without proper authorization. | |
| Title | Wiki.js through 2.5.314 Authorization Bypass via GraphQL Tag Omission | |
| First Time appeared |
Requarks
Requarks wiki.js |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:requarks:wiki.js:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Requarks
Requarks wiki.js |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-16T20:32:34.741Z
Reserved: 2026-09-16T19:15:39.714Z
Link: CVE-2026-92774
No data.
Status : Received
Published: 2026-09-16T21:17:26.247
Modified: 2026-09-16T21:17:26.247
Link: CVE-2026-92774
No data.
OpenCVE Enrichment
No data.
Weaknesses