CVE-2026-26477: High severity DokuWiki DokuWiki vulnerability
Published Apr 3, 2026
·Updated
An issue in Dokuwiki v.2025-05-14b "Librarian" [56.2] allows a remote attacker to cause a denial of service via the mediauploadxhr() function in the media.php file
Affected Software
1 affected component
DokuWiki DokuWiki=2025-05-14b
Event History
Apr 3, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-26477?
The severity of CVE-2026-26477 is rated high, with a score of 7.5.
2
What is CVE-2026-26477?
CVE-2026-26477 is a vulnerability in DokuWiki v.2025-05-14b that allows a remote attacker to cause a denial of service through the media_upload_xhr() function.
3
How do I fix CVE-2026-26477?
To mitigate CVE-2026-26477, upgrade to the latest version of DokuWiki that addresses this vulnerability.
4
What are the potential impacts of CVE-2026-26477?
The potential impact of CVE-2026-26477 is the possibility of a denial of service that could disrupt DokuWiki functionality.
5
When was CVE-2026-26477 published?
CVE-2026-26477 was published on April 3, 2026.