Wiki.js through 2.5.314 fails to require path separators when matching START and END page rules, allowing attackers to access pages sharing a prefix with authorized folders. Users granted access to a folder can read and modify unrelated pages with matching prefixes, bypassing intended access controls.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 16 Sep 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Wiki.js through 2.5.314 fails to require path separators when matching START and END page rules, allowing attackers to access pages sharing a prefix with authorized folders. Users granted access to a folder can read and modify unrelated pages with matching prefixes, bypassing intended access controls. | |
| Title | Wiki.js through 2.5.314 Path Prefix Matching Authorization Bypass | |
| First Time appeared |
Requarks
Requarks wiki.js |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:requarks:wiki.js:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Requarks
Requarks wiki.js |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-16T20:32:36.130Z
Reserved: 2026-09-16T19:15:40.413Z
Link: CVE-2026-92776
No data.
Status : Received
Published: 2026-09-16T21:17:26.547
Modified: 2026-09-16T21:17:26.547
Link: CVE-2026-92776
No data.
OpenCVE Enrichment
No data.
Weaknesses